Language Selection

English French German Italian Portuguese Spanish

Phishing Scam Targets Windows Update

Filed under
Microsoft
Security

A phishing scam emulating the Windows Update Service hit Australia yesterday, designed to not only emulate the update page perfectly, but circumvent current antivirus, spyware and adware programs.

The spam e-mail directs users to a page that pulls graphics from the Microsoft.com Web site and then recreates the page asking users to download a Windows update that is actually a malicious .exe file.

Director of SurfControl, Charles Heunemann, said the company discovered the virus late last night and that current heuristics and signatures used by core antivirus vendors are not picking up the malicious code.

"We are still trying to get to the bottom of it," Heunemann said.

"It is not a malicious attack for network resources but appears to send a message to the Internet advertising itself as a zombie machine - we think the .exe file pulls other code to turn the machine into a spamming server.

"The actual e-mail looks like a Microsoft e-mail but I don't think it is the practice for Microsoft to ask users to update their operating system by launching a link from an e-mail."

The virus, titled Wupdate-20050401, installs an executable file into the Windows directory and adds a startup service. When it is running the program takes up 100 percent of the CPU power, controlling the CPU by forcing it to perform continuous processes.

Microsoft security product manager Ben English said this is just one of many scams they are currently monitoring, adding that it is not unique.

"There are effective defences against these types of scams and we advise users to follow some simple guidelines," English said.

"Microsoft is aware of the SurfControl notice regarding the spoofing scam of Windows update and our advice to customers remains the same.

"Microsoft never attaches software updates to our security e-mail notifications; we never send notices about security updates or incidents until after we publish information about them on our Web site and if you suspect that an e-mail message is not legitimate, do not click any hyperlinks within it."

Sophos' Asia Pacific head of technology, Paul Ducklin, was aware of the program in question and said despite all the technology in the world, education and informed decisions by users will always be the best resort to stopping malware.

"Even if all other defences are down, with Trojan malware if a person doesn't click on it, it won't work - they all involve, to some extent, collaboration with users," Ducklin said.

"Three ways to block them include having software to prevent a suspicious program, using programs at the gateway to block .exe files and of course user education and information."

More in Tux Machines

Munich Switching to Windows from Linux Is Proof That Microsoft Is Still an Evil Company

Reports about the city of Munich authorities that are considering the replacement of Linux with Microsoft products mostly comes from one man, the Deputy Mayor of Munich, who is also a long-term self-declared Windows fan. Munich is the poster child for the adoption of a Linux distribution and the replacement of the old Windows OS. It provided a powerful incentive for other cities to do the same, and it's been a thorn in Microsoft's side for a very long time. The adoption of open source software in Munich started back in 2004 and it took the local authorities over 10 years to finish the process. It's a big infrastructure, but in the end they managed to do it. As you can imagine, Microsoft was not happy about it. Even the CEO of Microsoft, Steve Ballmer, tried to stop the switch to Linux, but he was too late to the party. Read more

Dangling the Linux Carrot

Sometimes the direct sell method isn’t the best way to close the deal. How do you think the whole “play hard to get” thing got traction throughout the years? That method is successful in any number of applications. And really, I wasn’t wearing my Linux Advocacy hat that evening…I was just a guy relaxing after a day’s work. Read more

Red Hat Sets New 12-Month High at $61.97 (RHT)

They now have a $70.00 price target on the stock, up previously from $57.00. Three equities research analysts have rated the stock with a hold rating and eighteen have issued a buy rating to the company’s stock. Red Hat has an average rating of “Buy” and an average price target of $63.50. Read more

Systemd 216 Piles On More Features, Aims For New User-Space VT

Lennart Poettering announced the systemd 216 release on Tuesday and among its changes is a more complete systemd-resolved that has nearly complete caching DNS and LLMNR stub resolver, a new systemd terminal library, and a number of new commands. The systemd 216 release also has improvements to various systemd sub-commands, an nss-mymachines NSS module was added, a new networkctl client tool, KDBUS updates against Linux 3.17's memfd, networkd improvements, a new systemd-terminal library for implementing full TTY stream parsing and rendering, a new systemd-journal-upload utility, an LZ4 compressor for journald, a new systemd-escape tool, a new systemd-firstboot component, and much more. Read more