On TV.com: How to Save HEROES
BNET Business Network:
BNET
TechRepublic
ZDNet

June 18th, 2009

Fake Microsoft patches themed malware campaigns spreading

Posted by Dancho Danchev @ 7:57 am

Categories: Anti Virus, Botnets, Browsers, Hackers, Malware, Microsoft, Patch Watch, Spam and Phishing

Tags: Malware, Social Engineering, Microsoft Corp., Malware Campaign, Spyware, Adware & Malware, Cyberthreats, Microsoft Outlook, Viruses And Worms, Security, Dancho Danchev

Researchers from Computer Associates (NASDAQ:CA) and Sophos are reporting on three currently active malware campaigns using fake Microsoft patch themes as a social engineering tactic to spread over email.

The first one is spreading as an “Important Windows XP/Vista Security Update” and is offering a bogus Conficker removal tool, the second is using an “Outlook re-configuration” — also spammed earlier this month — and the third one is using an out-of-the-band “Update for Microsoft Outlook / Outlook Express (KB910721)” theme, which in reality is nothing else but a trojan.

The fake Conficker removal tool campaign has been active for over a week now, with Symantec pointing that not only are the authors unable to make the difference between Troj/Brisv.A and Conficker, but also, they misspelled Conficker as ConFlicker in between attaching their malware to Symantec’s original removal tool in an attempt to build more legitimatecy into the campaign.

A similar fake “Conficker Infection Alert” spam campaign redirecting to scareware took place in April, however, despite the fact that cybercriminals continue sticking to the cyclical pattern of the “Microsoft security update/patch” social engineering theme, compared to previous campaigns where the timing was perfect, in this latest one it thankfully isn’t.

The second, Outlook re-configuration campaign is serving Outlook_update.exe through several legitimate and logically compromised web sites, next to the purely malicious ones. Interestingly, the third campaign promoting the fake Outlook critical update has directly attached the executable officexp-KB910721-FullFile-ENU.exe to the email, indicating their lack of experience in such campaigns.

With a well known pattern of abusing the momentum advantage for malicious purposes by hijacking emerging news stories or events (Swine flu email scams circulating; The Web’s most dangerous keywords to search for; Cybercriminals syndicating Google Trends keywords to serve malware; Cybercriminals hijack Twitter trending topics to serve malware), it shouldn’t take long before Iran’s massively covered election starts appearing in malicious campaigns.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 21 Talkback(s)
a complete idiot
What you forget is that the "audience" consists of many newbies, gullible and even desparate people who are not yet experienced and don't even yet know the information they need is available to them. ... (Read the rest)
Posted by: twaynesdomain Posted on: 07/04/09 You are currently: a Guest | | Terms of Use
You have to be a complete idiot to....  NeoGeneration | 06/18/09
Sadly  NStalnecker | 06/18/09
I Couldn't Agree More  robertmro | 06/19/09
Bogus Patches...  Lost Cause? | 06/19/09
Here's some technology you use everyday  stillgolfing | 06/23/09
Why should they?  pico_D | 06/26/09
Yoyr name says it all NeoG...  cbmjb | 06/22/09
Windows update is only about 98% reliable  914four | 06/23/09
a complete idiot  twaynesdomain | 07/04/09
RE: Fake Microsoft patches themed malware campaigns spreading  info@... | 06/19/09
True.  phatkat | 06/19/09
RE: Fake Microsoft patches themed malware campaigns spreading  donaldfiander@... | 06/19/09
RE: Fake Microsoft patches themed malware campaigns spreading  theguru1995@... | 06/19/09
It depenz...  valvestate@... | 06/19/09
yes, be concerned  catseverywhere@... | 06/19/09
yes, be concerned  theguru1995@... | 06/19/09
While I agree with you...  914four | 06/23/09
No  NStalnecker | 06/22/09
RE: Fake Microsoft patches themed malware campaigns spreading  DrMicro | 06/21/09
RE: Fake Microsoft patches themed malware campaigns spreading  rlohmann@... | 06/22/09
RE: Fake Microsoft patches themed malware campaigns spreading  gennx30 | 06/29/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here