Feeds

Alicia Keys hit by MySpace Trojan hack

Fallin'

Top three mobile application threats

This story was updated on Saturday, 10th November 2007 00:21 GMT to report additional details.

Multiple MySpace pages have been hacked in a bid to spread malware.

Targeted pages, including the site of R&B star Alicia Keys, have been loaded with links to Trojan horse malware that poses as a fake codec. As well as attempting to load the malware through a browser exploit the booby-trapped sites also attempt to trick users into downloading the fake codec.

Instead of using an iFrame injection method the poisoned profile uses an image map, so users clicking on anything over an area of a contaminated profile close to a pukka link will be taken to a maliciously-constructed website, hosted in China. The attack was discovered by Roger Thompson of Exploit Prevention Labs, who's posted an explanation of the attack along with a video here.

The discovery comes more than a week after researcher Chris Boyd published this post found similar shenanigans on myspace pages. The pages, Boyd found, had transparent overlays that linked to websites that tried to install malware, either by tricking a user into installing faux media codecs or by attempting to exploit vulnerable browsers. Thompson issued an apology to Boyd. "I didn't steal any of your work, and didn't mean to steal your thunder," he wrote.

As Thompson notes the beauty of the attack is that MySpace pages are such a pig's breakfast of clutter and multimedia files that would-be victims won't be surprised about having to load a codec and therefore all the more likely to fall for the ploy. It's unclear how many pages have been infected.

MySpace has increasingly become the subject of security concerns. In October 2005, a bug in MySpace's site design was misused to create a self-propagating cross-site scripting worm. More recently MySpace pages have been used to spread spyware, a trend continued in a more sophisticated form with the latest fake codecs attack. ®

Combat fraud and increase customer satisfaction

Whitepapers

Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Mainstay ROI - Does application security pay?
In this whitepaper learn how you and your enterprise might benefit from better software security.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.