Fake ‘Facebook Account Update’ and ‘Myspace Password Reset Confirmation’ Phishing Emails Contain Malware

GoldSparrow By GoldSparrow in Computer Security | 0 views
Rate it:
1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...

If you are an active user of Facebook or MySpace, then you may want to take note of the recent scamming and phishing attacks that could install malware on your computer.

Computer users have encompassed various phishing attacks through Facebook and MySpace spam messages. These messages were found to be laden with malicious links that redirect users to a phishing site where login credentials can be obtained.

The latest malicious spam can persuade users to log in by using a false link. The email pretends to make a computer user’s online experience more secure and pleasing by updating their credentials. The fake messages allege to come from either Facebook or MySpace. Users will receive an email that appears to be an official Facebook invite or a password reset confirmation but actually contains a zip file that, if opened, loads an .exe file, which was found to be the vicious Trojan.Bredolab parasite. By using this nasty parasite, hackers are not only enabled to gain a user’s password and user name but, access Facebook accounts, computer files and bank accounts.

If an unsuspecting user clicks on the ‘update’ button, then he or she will be redirected to a bogus Facebook site where they will be asked to enter a password for completion of the updating process. When the Facebook user does this, the hacker takes position of their password enabling them to perform other malicious actions with the user’s account. The misleading subject line for the phishing emails usually says something along the lines of the following:

  • ‘Facebook account update’
  • ‘New login system’
  • ‘Facebook update tool’

The malicious email subject lines for the MySpace phishing emails may read:

  • ‘Myspace Password Reset Confirmation’
  • ‘Myspace office on fire’
  • ‘Myspace was ruined’

The fake MySpace message will simply state that their password was reset and that the new password is included in an attached document which is another devilish approach to tricking computer users into giving up their login credentials.

What should you do to avoid such malicious attacks on Facebook and MySpace?

It’s strongly advised to check the website of the organization that sent the email. Users are also encouraged to never provide personal information such as your login and password. It is also a good idea to update your anti-virus software. All computer users should be vigilant of dubious attachments and password reset requests while at the same time be careful when clicking links to websites within email messages. Users should note that legitimate websites will never send an attachment to reset a password.

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Furl
  • StumbleUpon
  • Technorati
  • YahooMyWeb
This entry was posted on 11/10/09 and is filed under Computer Security. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Comment

Note: Abusive comments are not allowed. Please do not post comments regarding technical support issues. ESG customers that have issues with SpyHunter should open a customer support ticket.

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word

Poll

How much money have you spent trying to rid your PC of spyware?
View Results
Follow Us on Twitter

Archives

Home Sitemap RSS Feed Privacy Policy End User License Agreement Copyright 2003-2010. Enigma Software Group USA, LLC. All Rights Reserved.