Fake Microsoft security alert includes Trojan patch

InfoWorld | at | by Mike

A new wave of spam that disguises itself as a Microsoft security bulletin contains a link to malicious software that gives attackers complete access to the infected machine, security researchers are reporting.

The e-mail, which began circulating late Tuesday, identifies itself as Microsoft Security Bulletin MS05-039, and offers a link to what it claims is a patch against the Sober Zafi and Mytob worms.

In fact, there is no such thing as Microsoft Security Bulletin MS05-039, and real Microsoft security bulletins offer links to a Microsoft download site, rather than to the patches themselves, said Mikko Hyppönen, director of antivirus research at F-Secure