We have received reports of perpetrators spamming fake Microsoft security bulletin e-mails. These are another row of highly targeted attacks that appear as notifications of “security updates” or “security patch for a 0-day vulnerability”.
The subject lines seen are the like of:
“Microsoft Security Bulletin MS07-0065 – Critical Update”
“Microsoft Security Bulletin MS07-0065″
These e-mails are obvious spoofs, that contain a link to a “supposedly” security patch. But the link actually downloads a malicious trojan from a rigged website. The targeted e-mails are highly personalized with a formal greeting, full name with organization, the reason for the e-mail (like mentioning of a subscription to Microsoft Windows Update mailing list), fake Windows License key, and a download link to the fake security patch.
Please be weary of such fraudulent e-mails. Always verify before clicking a link by hovering over the link to see if it is indeed a legitimate site or just a phishing attempt. Although this can be spoofed as well, in that case just use your common sense
[...] YouTube Link to Article microsoft windows Another flavour of targetted attacks – fake Microsoft Security Bulletin » Posted at Authentium Virus Blog on Thursday, June 28, 2007 Another flavour of targetted attacks – fake Microsoft Security Bulletin June 28, 2007 11: … of a subscription to Microsoft Windows Update mailing list), fake Windows License key, and a download link … 11 AM We have received reports of perpetrators spamming fake Microsoft security bulletin e-mails View Entire Article » [...]