Language Selection

English French German Italian Portuguese Spanish

Phishing Scam Targets Windows Update

Filed under
Microsoft
Security

A phishing scam emulating the Windows Update Service hit Australia yesterday, designed to not only emulate the update page perfectly, but circumvent current antivirus, spyware and adware programs.

The spam e-mail directs users to a page that pulls graphics from the Microsoft.com Web site and then recreates the page asking users to download a Windows update that is actually a malicious .exe file.

Director of SurfControl, Charles Heunemann, said the company discovered the virus late last night and that current heuristics and signatures used by core antivirus vendors are not picking up the malicious code.

"We are still trying to get to the bottom of it," Heunemann said.

"It is not a malicious attack for network resources but appears to send a message to the Internet advertising itself as a zombie machine - we think the .exe file pulls other code to turn the machine into a spamming server.

"The actual e-mail looks like a Microsoft e-mail but I don't think it is the practice for Microsoft to ask users to update their operating system by launching a link from an e-mail."

The virus, titled Wupdate-20050401, installs an executable file into the Windows directory and adds a startup service. When it is running the program takes up 100 percent of the CPU power, controlling the CPU by forcing it to perform continuous processes.

Microsoft security product manager Ben English said this is just one of many scams they are currently monitoring, adding that it is not unique.

"There are effective defences against these types of scams and we advise users to follow some simple guidelines," English said.

"Microsoft is aware of the SurfControl notice regarding the spoofing scam of Windows update and our advice to customers remains the same.

"Microsoft never attaches software updates to our security e-mail notifications; we never send notices about security updates or incidents until after we publish information about them on our Web site and if you suspect that an e-mail message is not legitimate, do not click any hyperlinks within it."

Sophos' Asia Pacific head of technology, Paul Ducklin, was aware of the program in question and said despite all the technology in the world, education and informed decisions by users will always be the best resort to stopping malware.

"Even if all other defences are down, with Trojan malware if a person doesn't click on it, it won't work - they all involve, to some extent, collaboration with users," Ducklin said.

"Three ways to block them include having software to prevent a suspicious program, using programs at the gateway to block .exe files and of course user education and information."

More in Tux Machines

Red Hat News

today's howtos

Tablets, Chromebooks, and GNU/Linux Laptops

  • Diskio Pi Wants to Be the Ultimate Open Source Tablet Powered by Raspberry Pi
    A new open source project hit Kickstarter a few days ago, and it caught our attention because it appears to be a versatile machine that's fully compatible with Raspberry Pi and Odroid single-board computers. Created by Guillaume Debray, an optician with 10+ years experience in making and selling glasses, yet a passionate computer engineer with deep knowledge of programming and hardware assembly and manufacturing processes, the Diskio Pi project wants to be the ultimate open source tablet powered by Raspberry Pi. Diskio Pi is the result of 18 months of development, and, in fact, it seems to be some sort of versatile device built on top of a single-board computer. It's currently compatible with Raspberry Pi 2, Raspberry Pi 3, Raspberry Pi Zero, Odroid C1, and Odroid C2 SBCs, and can run Ubuntu, Debian, Raspbian Pixel, or Android.
  • The new Entroware Hybris could make a reasonable Linux gaming laptop
    Entroware, the UK-based Linux hardware vendor have released two newer laptops and one of them could be a reasonable gaming unit.
  • Chrome OS' Upcoming Night Light Feature Gets "Sunset to Sunrise" Automatic Mode
    The fantastic Chrome OS team over at Google is on a rampage, and after teasing us with the revamped sign-in/lock screens and new power management settings, today François Beaufort revealed yet another cool feature for our Chromebooks. This time, the developer announced on his Google+ page that the Chrome OS team is working on implementing an automatic "Sunset to Sunrise" mode for the upcoming Night Light feature, which should improve our sleep after using a Chromebook at night and ensures reduced strain on the eyes by limiting the amount of blue light emitted by the display.
  • CrossOver for Android Lets You Run Windows Apps on Intel-Based Chromebooks
    CodeWeavers‏, the commercial company behind the well-known CrossOver for Linux and Mac application that lets users install and run Windows apps and games is still working to release an Android version. Dubbed CrossOver Android, the project has been in development for the past year, and while it's still in an Alpha state, it looks like it is already capable of running Windows software on Intel-based Chromebooks and Android tablets. Since then, the project kept updating CrossOver for Android with new features.
  • Quick Reminder For The 2017 Linux Laptop Survey

Open Source Adreno Project “Freedreno” Receives New Update

Users of Freedreno, the open-source graphics driver support for Adreno on Linux distributions, will be pleased to know that a new update has been released in the past week. Lead developer Rob Clark discussed many of the details in his blog, which highlight above all the support for Adreno 500 series GPUs. Among the highlights include compute shaders for OpenGL and OpenGL ES, improved performance and improved Linux distribution support. Read more