11/10/2007

Malware Planted on MySpace Once Again

Filed under: Aviran Mordo @ 10:29 am

Attackers are piggybacking on the fame of R&B recording artist Alicia Keys to spread their malware Relevant Products/Services over the Web. Keys’ MySpace page has been infected with malicious software.

Exploit Prevention Labs discovered the attack, one of several targeted MySpace pages. French funk band Greements of Fortune and Glasgow rock band Dykeenies were also targets of the Web-based attack.

“When a visitor visits the infected page, they’re first hit by an exploit which installs malware in the background if they’re not fully patched against the latest security Relevant Products/Services vulnerabilities, and next they’re presented with a fake codec which tells them they need to install a codec to view the video,” said Roger Thompson, CTO at Exploit Prevention Labs. “So even if they’re patched, they can fall victim to the exploit.”

Specifically, visitors to these MySpace pages are directed to co8vd.cn/s. This appears to be a Chinese malware site. If the visitors accept the code installation, the site installs malicious software.

 

Leave a Reply

You must have Javascript enabled in order to submit comments.

All fields are optional (except comment).
Some comments may be held for moderation (depends on spam filter) and not show up immediately.
Links will automatically get rel="nofollow" attribute to deter spammers.

Powered by WordPress