Feeds

Alicia Keys hit by MySpace Trojan hack

Fallin'

Intelligent flash storage arrays

This story was updated on Saturday, 10th November 2007 00:21 GMT to report additional details.

Multiple MySpace pages have been hacked in a bid to spread malware.

Targeted pages, including the site of R&B star Alicia Keys, have been loaded with links to Trojan horse malware that poses as a fake codec. As well as attempting to load the malware through a browser exploit the booby-trapped sites also attempt to trick users into downloading the fake codec.

Instead of using an iFrame injection method the poisoned profile uses an image map, so users clicking on anything over an area of a contaminated profile close to a pukka link will be taken to a maliciously-constructed website, hosted in China. The attack was discovered by Roger Thompson of Exploit Prevention Labs, who's posted an explanation of the attack along with a video here.

The discovery comes more than a week after researcher Chris Boyd published this post found similar shenanigans on myspace pages. The pages, Boyd found, had transparent overlays that linked to websites that tried to install malware, either by tricking a user into installing faux media codecs or by attempting to exploit vulnerable browsers. Thompson issued an apology to Boyd. "I didn't steal any of your work, and didn't mean to steal your thunder," he wrote.

As Thompson notes the beauty of the attack is that MySpace pages are such a pig's breakfast of clutter and multimedia files that would-be victims won't be surprised about having to load a codec and therefore all the more likely to fall for the ploy. It's unclear how many pages have been infected.

MySpace has increasingly become the subject of security concerns. In October 2005, a bug in MySpace's site design was misused to create a self-propagating cross-site scripting worm. More recently MySpace pages have been used to spread spyware, a trend continued in a more sophisticated form with the latest fake codecs attack. ®

Top 5 reasons to deploy VMware with Tegile

Whitepapers

Choosing cloud Backup services
Demystify how you can address your data protection needs in your small- to medium-sized business and select the best online backup service to meet your needs.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.