Language Selection

English French German Italian Portuguese Spanish

Phishing Scam Targets Windows Update

Filed under
Microsoft
Security

A phishing scam emulating the Windows Update Service hit Australia yesterday, designed to not only emulate the update page perfectly, but circumvent current antivirus, spyware and adware programs.

The spam e-mail directs users to a page that pulls graphics from the Microsoft.com Web site and then recreates the page asking users to download a Windows update that is actually a malicious .exe file.

Director of SurfControl, Charles Heunemann, said the company discovered the virus late last night and that current heuristics and signatures used by core antivirus vendors are not picking up the malicious code.

"We are still trying to get to the bottom of it," Heunemann said.

"It is not a malicious attack for network resources but appears to send a message to the Internet advertising itself as a zombie machine - we think the .exe file pulls other code to turn the machine into a spamming server.

"The actual e-mail looks like a Microsoft e-mail but I don't think it is the practice for Microsoft to ask users to update their operating system by launching a link from an e-mail."

The virus, titled Wupdate-20050401, installs an executable file into the Windows directory and adds a startup service. When it is running the program takes up 100 percent of the CPU power, controlling the CPU by forcing it to perform continuous processes.

Microsoft security product manager Ben English said this is just one of many scams they are currently monitoring, adding that it is not unique.

"There are effective defences against these types of scams and we advise users to follow some simple guidelines," English said.

"Microsoft is aware of the SurfControl notice regarding the spoofing scam of Windows update and our advice to customers remains the same.

"Microsoft never attaches software updates to our security e-mail notifications; we never send notices about security updates or incidents until after we publish information about them on our Web site and if you suspect that an e-mail message is not legitimate, do not click any hyperlinks within it."

Sophos' Asia Pacific head of technology, Paul Ducklin, was aware of the program in question and said despite all the technology in the world, education and informed decisions by users will always be the best resort to stopping malware.

"Even if all other defences are down, with Trojan malware if a person doesn't click on it, it won't work - they all involve, to some extent, collaboration with users," Ducklin said.

"Three ways to block them include having software to prevent a suspicious program, using programs at the gateway to block .exe files and of course user education and information."

More in Tux Machines

Leftovers: Ubuntu

  • Ubuntu-based Smartphones And Tablets Sound Good, On Paper, But...Do They Make Any Sense?
    As I previously stated in a recent article, I'm a huge fan of Ubuntu as a desktop operating system. It's friendly, reliable, consumes little resources and is largely virus-free.
  • Elementary OS 0.4 ‘Loki’ expected to be based on Ubuntu 16.04
    Elementary OS 0.4 ‘Loki’ coming soon, to be based on Ubuntu 16.04 and have plenty of new features
  • BQ Aquaris M10 Ubuntu Edition tablet - The heat is on
    Some investments are financial. Some are emotional. When it comes to Linux on tablets, my motives are mostly of the latter kind. I was super-excited to learn BQ was launching a tablet with Ubuntu, something that I have been waiting for a good solid three years now. We had the phone released last spring, and now there's a tablet. The cycle is almost complete. Now, as you know, I was only mildly pleased with the Ubuntu phone. It is a very neat product, but it is not yet as good as the competitors, across all shades of the usability spectrum. But this tablet promises a lot. Full HD, desktop-touch continuum, seamless usage model, and more. Let us have a look.
  • Kubuntu-16.04 — a review
    The kubuntu implementation of Plasma 5 seems to work quite well. It’s close to what I am seeing in other implementations. It includes the Libre Office software, rather than the KDE office suite. But most users will prefer that anyway. I’m not a big fan of the default menu. But the menu can easily be switched to one of the alternative forms. I’ve already done that, and am preferring the “launcher based on cascading popup menus”. If you are trying kubuntu, I suggest you experiment with the alternative formats to see which you prefer.
  • Ubuntu 16.04 LTS Review: Very Stable & Improved, Buggy Software Center, Though
    In almost all the occasions that I tested Ubuntu LTS releases, quite rightly so, they’ve always worked better than the non-LTS releases. And this Ubuntu 16.04 LTS, the 6th of such release is no exception. This one actually is even more impressive than the others because it has addressed some security related issues and even although not critical, subtle issues that I mentioned in the review. As far as the performance was concerned, Ubuntu 16.04 LTS was only largely outperformed by the memory usage where there is a large increase in memory usage. Other than that, those numbers look pretty good to me. That ‘.deb’ file issues with the Software Center is the only major concern that I can come up with. But I’m sure it’ll be fixed very soon.

Devuan Beta, Stumbling Tumbleweed, Ubuntu Too

Today in Linux news Debian-fork Devuan is forging ahead with its plans to create a distribution offering init freedom by releasing a beta for testers. Douglas DeMaio posted today that openSUSE Tumbleweed snapshots have halted due to glibc upgrade rebuilds. Dedoimedo reviewed the BQ Aquaris M10 and liliputing.com posted of another Ubuntu laptop for sale. And finally, the Hectic Geek reviewed Ubuntu 16.04 and Neil Rickert reviewed Kubuntu 16.04. Read more Also: Devuan releases beta Devuan Jessie - beta release announcement

Devuan Jessie beta released

dear Init Freedom Lovers, once again the Veteran Unix Admins salute you. As promised two years ago with the first declaration of Exodus from Debian, today we can proudly state: we do not go gentle into that good night. Now has come the time to announce the Beta release of Devuan. Debian GNU+Linux is a fork of Debian without systemd, on its way to become much more than that. This Beta release marks an important milestone towards the sustainability and the continuation of Devuan as an universal base distribution. Read more Also: Beta Released Of Devuan, The Systemd-Free Version Of Debian

GNOME News