Fake Microsoft Security Update Email Includes Haxdoor Trojan
Posted 10/16/08 at 04:07:25 PM | by Mark Edward Soper

I know it, you know it, almost everybody that reads Maximum PC knows it - but that doesn't mean that your family, your co-workers, or your bosses know it. What's it? Simply this: Microsoft never - repeat never - sends out security updates via email.
Cnet reports that yet another fake security email purporting to be from Microsoft is busy delivering a nasty Trojan called Haxdoor to unwary emailboxes near you.
The email, ironically enough, claims that "Since public distribution of this Update through the official website http://www.microsoft.com would have result in efficient creation of a malicious software, we made a decision to issue an experimental private version of an update for all Microsoft Windows OS users." And, it's signed "Steve Lipner, Directory of Security Assurance, Microsoft Corp."
Well, at least the bad guys got Steve's name right. However, he's actually senior director of security engineering strategy in Microsoft’s Trustworthy Computing Group, according to a recent interview.
The message (minus the Trojan, of course), is available at the Microsoft Malware Protection Center blog, where you can see for yourself the classic hallmarks of a fake message: a shaky command of the English language, sentence construction that's so stiff it looks as if it belongs on a Victorian-era calling card, and off-the-wall sentiments that show it was adapted from a different con job document: "We apologize for any inconvenience this back order may be causing you." Back order? Whaat? I didn't order any malware!
If you've been called in by baffled family, friends, or co-workers only after Haxdoor's done its work (system slowdowns, popup ads and other nasty business are typical symptoms), check these links for help:
- Microsoft Malware Protection Center writeup
- F-Secure writeup
- Symantec writeup and free removal tool
- Sunbelt Software writeup
- Sophos Software writeup
After you solve the problem, remind them: Microsoft never - repeat never - sends out security updates via email.
Know somebody who's been hexed by Haxdoor? Have a clever way to get rid of it? Seen other recent examples of Haxdoor fakery? Hit Comment and share your stories.
How obvious
Submitted by Number Six on Thu, 2008-10-16 15:14
The e-mail itself refers to recent updates for Win 98 and Win Me. Yeah, sure. There are also numerous tell-tale signs that this is a fake. Really, I expect better from the hax0rz community.
1 NEW COMMENT(S) | 54 TOTAL COMMENTS









