Sophos warns over fake MS update worm

By

Spammers target users with bogus attachment.

Security firm Sophos is warning Windows users to beware of a fake security update scam that installs a worm in target machines.

Sophos warns over fake MS update worm

The attack arrives in the form of a spam email that appears to come from Microsoft, warning users to update their operating system.

Anyone opening the email is advised to follow instructions, which involve installing the attached KB453396-ENU.zip file.

Microsoft never sends out such emails, instead using its own update system, but Sophos believes the scam could fool some users because it looks official.

“In the current example, they've spammed out an email containing a worm, which even quotes the real name of a senior member of Microsoft's security team - Steve Lipner - to try to fool you into believing it is genuine,” the company said on its Naked Security blog.

The emails have a subject line of "Update your Windows".

This article originally appeared at pcpro.co.uk

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © Alphr, Dennis Publishing
Tags:

Most Read Articles

First npm worm "Shai-Hulud" released in supply chain attack

First npm worm "Shai-Hulud" released in supply chain attack

"VoidProxy" PhishKit targets Google and Microsoft users

"VoidProxy" PhishKit targets Google and Microsoft users

Apple adds "mercenary spyware" protection to new A19 chip

Apple adds "mercenary spyware" protection to new A19 chip

Phishing attack nets enormous npm supply chain compromise

Phishing attack nets enormous npm supply chain compromise

Log In

  |  Forgot your password?