Spotify users hit by Malware attack

Malvertising problem for music streamer

Spotify users hit by Malware attack

29 March 2011 12:40 GMT / By Paul Lamkin

Spotify has admitted that it has been the victim of a security exploit and apologised to users infected via a malware-riddled advert that appeared on the Windows desktop version of the popular music streaming platform.

The malvertising incident first struck on 24 March at 11.30am UK time, and the worrying aspect is that users didn't even need to click the infected ad to allow it to access their machines - it worked via the Blackhole Exploit Kit, and was able to do its dirty work without Spotify fans even noticing.

"The application will render the ad code and run it as if it were run inside a browser," said Websense's Patrik Runald.

"This means that the Blackhole Exploit Kit works perfectly fine and it's enough that the ad is just displayed to you in Spotify to get infected, you don't even have to click on the ad itself.

"So if you had Spotify open but running in the background, listening to your favourite tunes, you could still get infected."

The rogue advert connected machines to a site where the exploit kit tried several vulnerabilities to infect the user. If successful, it would then install the fake anti-virus program Windows Recovery.

Users with real AV protection should have had no problems, and Spotify removed all third party adverts as a precautionary measure as soon as it was aware of the incident. The hack only affected Spotify free users.

"We sincerely apologise to any users affected. We'll continue working hard to ensure this does not happen again and that our users enjoy Spotify securely and in confidence," read a statement from the Swedish digital music giant.

Avast has stated that 59 per cent of attacks occurred in Sweden, with 40 per cent of infection reports coming from the UK.

Via: bbc.co.uk

Full tags
Digital music, Viruses And Malware, Streaming, Spotify, Online, Software

share print story pdf email story

Recommended articles

Recommended articles from around the web

Loading

Best iPad 2 apps

We detail the best iPad 2 and iPad apps in the app store Which iPad app should you download?

Best new iPad apps

We detail the best iPad apps in the app store for your new Retina Display Which iPad app should you download?

Windows 8

First Look: Windows 8 Consumer Preview reviewed

The new iPad

The new iPad: Everything you need to know

Pocket-lint poll

Q. Does the Samsung Galaxy S III deliver what you hoped for?

Vote YES Vote NO

» LAST TIME
When asked Would you switch from iOS to Android? 54% said yes and 46% said no