by Jack McCarthy

Michael Jackson suicide e-mail hoax is a Trojan attack

news
Jun 10, 20052 mins

E-mails saying pop star Michael Jackson has attempted suicide are in fact a Trojan virus, according to Sophos, a British anti-virus company.

Sophos said it has identified hundreds of the spam messages that exploit public attention focused on Jackson, currently on trial on child molestation charges.

The spam e-mails, under the heading, “Re: Suicide aattempt,” read, “Last night, while in his Neverland Ranch, Michael Jackson has made a suicidal attempt.”

The e-mails offer a link to more information. However, when users click on the link they are taken to a Website that installs malicious code onto their PCs.

“If you click on the link the Website displays a message saying it is too busy, which may not surprise people who think it might contain genuine breaking news about Michael Jackson,” said Carole Theriault, security consultant at Sophos. “However, this is a diversionary tactic – because behind the scenes the website is downloading malware onto the user’s computer without their knowledge.”

Sophos security experts analysed the code downloaded by clicking on the link, and determined that it itself attempts to download another Trojan horse which Sophos detects as Troj/Borobt-Gen.

Jackson’s notoriety has attracted hackers in the past. In October 2004, Internet messages claiming that incriminating home videos belonging to Jackson had been discovered, actually linked to infected Web surfers with the Hackarmy Trojan horse, Sophos said. Janet Jackson’s Superbowl wardrobe malfunction also inspired virus attack.

“The sick minds behind viruses and other malware often exploit celebrity names and news stories in an attempt to infect as many people as possible,” Theriault said. “All computer users should be very careful about clicking on weblinks in unsolicited email or launching unknown attachments.”

Sophos said it recommends companies automatically update their corporate virus protec-tion, and filter attachments which may contain malicious code at the email gateway with a consolidated solution to defend against viruses and spam.