Multiple user pages on MySpace contain spoofed videos that appear to be from You Tube but are embedded with an installer for the Zango Cash Toolbar, researchers warned this week.
Zango agreed to a $3 million settlement this month with the Federal Trade Commission (FTC) after the agency accused the company of installing adware more than 70 million times, causing 6.9 billion pop-up ads.
The FTC said the firm used third parties to install adware onto victimized PCs, concealing the programs in screensavers, browser updates or free games.
The malicious spoofed YouTube pages advertise adult videos and redirect users via a "click here for full video" link to a Microsoft Windows media file that, once users accept the end-user licensing agreement, downloads a setup file from Zango Cash, according to researchers at Websense Security Labs.
Dan Hubbard, senior director for security and technology research at Websense, told SCMagazine.com today that YouTube and MySpace are inevitable targets for hackers because of their popularity.
"With Zango, it was reported that they were using this Microsoft (program) to get these applications downloaded and launched while a video was running, which is intriguing. Other than that, it's just the harvesting of the popularity of You Tube and MySpace," he said. "The whole user-created content, Web 2.0 paradigm leads me to believe that these types of attacks may happen more and more, because web property (administrators) will have trouble keeping up with the kinds of files they have to patrol."
The spoofed YouTube website is hosted in Amsterdam, according to Websense, and has a fraudulent domain name.
Click here to email Frank Washkuch Jr.