Hackers spam fake Microsoft security update
A clever attempt to take advantage of Microsoft’s ‘Patch Tuesday’.
Hackers are taking advantage of Patch Tuesday with a malicious Trojan email disguised as a Microsoft security update.
The email claims to come from Steve Lipnser at the address securityassurance@microsoft.com with the subject line "Security Update for OS Microsoft Windows." It asks you to run the file attached with the message and appears to coincide with Microsoft's genuine monthly patch cycle.
Microsoft never sends out security updates as email attachments, but the email tries to explain this by claiming it is "an experimental private version."
Graham Cluley, senior technology consultant at Sophos, said that running the attached file would infect Windows computer users with the Mal/EncPK-CZ Trojan horse and give hackers control of the PC.
He advised users: "They should always visit the genuine Microsoft website or use automatic updating processes to keep their systems current."
The fake update comes after Microsoft gave advanced notice of its monthly patch cycle for the first time.
A picture of the fake update is here.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
-
London races ahead of the rest of the UK in effective AI adoptionNews While most firms in the region say AI is bringing greater efficiency and stronger innovation, only a quarter of those outside have made it part of their core processes and decision-making
-
Ireland's DPC reports a 'significant' increase in AI-related engagementsNews The data protection authority said it's secured significant improvements in compliance and expects to see more cases involving agentic AI
-
Cisco sounds alarm over new Russian malware campaign hitting firms in US and EuropeNews UAT-11795 is weaponizing legitimate software such as WebEx and Zoom to dupe victims
-
CronRat Magecart malware uses 31st February date to remain undetectedNews The malware allows for server-side payment skimming that bypasses browser security
-
Mekotio trojan continues to spread despite its operators’ arrestsNews Hackers have used it in 100 more attacks since arrests
-
“Trojan Source” hides flaws in source code from humansNews Organizations urged to take action to combat the new threat that could result in SolarWinds-style attacks
-
What is Emotet?In-depth A deep dive into one of the most infamous and prolific strains of malware
-
Fake AnyDesk Google ads deliver malwareNews Malware pushed through Google search results
-
Hackers use open source Microsoft dev platform to deliver trojansNews Microsoft's Build Engine is being used to deploy Remcos password-stealing malware
-
Android users told to be on high alert after Cerberus banking Trojan leaks to the dark webNews The source code for the authenticator-breaking malware is available for free on underground forums