Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

December 21st, 2010, 16:56 GMT · By

Fake iTunes Email Alerts Lead Users to Drive-By Download

SHARE:

Adjust text size:


iTunes users targeted by malware distributors
Enlarge picture
A wave of fake iTunes emails falsely alerting recipients about their accounts facing suspension directs them to a Web page that tries to install malware on their computers.

The rogue emails are crafted to appear as if they originate from a contact@itunes.com address and bear a subject of "iTunes account may be suspended."

"Dear iTunes Customer, it is possible that your account password has been stolen. 4 different IP addresses have been used to login to your account within the last 24 hours. Please visit the bellow link and read what to do and how to contact support department," the message reads.

This sounds very much like a phishing scam, but Alex Eckleberry, general manager of the security software division at GFI, points out that the intention of the attackers is to silently infect users.

The cyber criminals behind the emails even try to earn people's trust noting in the email that "iTunes will never ask you for your password or any confidential information."

Satisfied that this is probably not a phishing attack, users might click on the link to see additional information.

In that case, they would be taken to a page mimicking an Apple support article entitled "How to report an issue with Your iTunes Store purchase."

The site might look benign, but in the background it loads scripts that try to exploit vulnerabilities in outdated versions of Flash Player, Java and even unpatched Windows installations, in order to download and install malware.

Such attacks are known as drive-by downloads and the exploitation occurs transparently to the victims. Users are strongly encouraged to keep their applications up to date and browse the Web with a capable antivirus installed.

Free programs like Secunia Personal Software Inspector can automate the task of patching popular applications.

TELL US WHAT YOU THINK:

1,291 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


ZBot Pushers Attack iTunes Store Users

New Phishing Attack Targets MobileMe Users

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM