Computer users are slowly starting to get the message that it is important to keep their machines up to date with the latest security patches.
The bad news is that cybercriminals are starting to exploit this very awareness for their own malicious purposes.
For example, a malware discovered by Sophos comes as a security update for accounting firm ADP.
The emails, which have the subject “ALERT From ADP: 2013 Anti-Fraud Service Security Update” or “2013 Anti-Fraud Security Update”, have an attached ZIP file containing a malicious payload.
Example of malicious e-mails.
Part of the malicious emails is as follows:
WARNING!
2013 Anti-Fraud Secure update
Dear ADP customer,
We are pleased to announce that ADP Payroll System has released security updates for your computer.
A new version of the security is available.
Our development division strongly recommends that you download this software update.
Contains new features:
The certificate is linked to the account holder's computer, which disables any fraudulent activity.
Any irregular activity on your account is detected by our security center
. Download the attachment. The update will be installed automatically with a single double-click.
We appreciate your partnership and are proud of the trust you place in us to process your payroll. As always, the ADP service team is happy to assist you with any questions you may have.
A user receiving the email after the well-known security patches for Internet Explorer and Java that we published in the past few days might well think that they will be acting smart if they run the attachment! The truth is that they will fall straight into the hackers' trap.
Sophos identifies the malware contained in the attachment as Mal/FakeAV-OY, a fake anti-virus program.
If your computer has a firewall, it may block the fake anti-virus's attempt to connect to the internet.
For example, the Windows firewall blocks the fake anti-virus.
This type of malware, also known as fake anti-virus, starts sending warnings that your computer is infected with malware. The software then offers to remove the infection, but first requires you to pay a certain amount.
Of course, if you make the mistake (for the second time) and give out your credit card details then don't be surprised if your problems multiply.
Watch the video from Sophos
The lesson here is clear. It's good to care about your computer's security, and download security updates when they are available, BUT you should also check who those updates come from.


