Malicious 'MySpace pages' install adware through fake You Tube video

By
Follow google news

Multiple user pages on MySpace contain spoofed videos that appear to be from You Tube but are embedded with an installer for the Zango Cash Toolbar, researchers warned this week.


Zango agreed to a $3 million settlement this month with the Federal Trade Commission (FTC) after the agency accused the company of installing adware more than 70 million times, causing 6.9 billion pop-up ads.

The FTC said the firm used third parties to install adware onto victimised PCs, concealing the programs in screensavers, browser updates or free games.

The malicious spoofed You Tube pages advertise adult videos and redirect users via a "click here for full video" to a Microsoft Windows media file that, once users accept the end-user licensing agreement, downloads a setup file from Zango Cash, according to researchers at Websense Security Labs. Dan Hubbard, senior director for security and technology research at Websense, told SCMagazine.com today that You Tube and MySpace are inevitable targets for hackers because of their popularity.

"With Zango, it was reported that they were using this Microsoft (program) to get these applications downloaded and launched while a video was running, which is intriguing. Other than that, it's just the harvesting of the popularity of You Tube and MySpace," he said. "The whole user-created content, Web 2.0 paradigm leads me to believe that these types of attacks may happen more and more, because web property (administrators) will have trouble keeping up with the kinds of files they have to patrol."

The spoofed You Tube website is hosted in Amsterdam, according to Websense, and has a fraudulent domain name.

Click here to email Frank Washkuch Jr.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Tags:

Most Read Articles

CBA builds two AI agents to boost cyber defences

CBA builds two AI agents to boost cyber defences

Researchers uncover 'Darksword' iPhone spyware

Researchers uncover 'Darksword' iPhone spyware

Stryker contains cyber attack on its Microsoft environment

Stryker contains cyber attack on its Microsoft environment

Exploited Google Chrome zero-days added to US must-patch list

Exploited Google Chrome zero-days added to US must-patch list

Log In

  |  Forgot your password?