|
With all the proliferation of phone home for update systems in
even trivial software packages these days, neophyte users
can easily get confused about legitimate upgrades and imposters.
So someone is trying to take advantage of this with an
automated version of an old school social engineering
attack via Skype spam.
Someone/something/.someone's-botnet on skype last night
contacted users who reported it to me. The messages were
formatted to resemble Microsoft update messages or an AV scan
with a link to click to update and/or repair malware in a number
of Microsoft products. None of the users who reported it to me
clicked on the link so its not clear what the installed malware
was after.
A series of users with the name "Scan Alert" followed by the registered
trade mark sign originating from a numeric range of skype userids
following the form:
scan.alert.o