Story image

Spotify Free hits sour note with infected ads

14 Oct 2016

Some users of the ad-supported music streaming service Spotify Free got more hits than they bargained for, according to numerous reports.

It all started on Tuesday (4th), when one of its users reported an issue to their forum. It read:

There’s something pretty alarming going on right now with Spotify Free. This started several hours ago. If you have Spotify Free open, it will launch – and keep on launching – the default Internet browser on the computer to different kinds of malware / virus sites. Some of them do not even require user action to be able to cause harm.

I have 3 different systems (computers) which are all clean and they are all doing this, all via Spotify – I am thinking it’s the Ads in Spotify Free.

Within a matter of hours, Twitter users were echoing these sentiments and indicating that browsers on Windows 10, MacOS and Ubuntu were launching and spawning the suspect ads.

Spotify was hit with a similar incident in 2011 when an ad that appeared directly in their Windows desktop software installed a bogus antivirus program.

At the time, Spotify noted that users running antivirus software were protected.

Spotify’s response indicated that one ad was responsible for spawning and re-spawning multiple malicious ads.

Commenting on the story, ESET’s Lysa Myers said: “Users need to be aware that free apps come with a cost  – of extra risk due to malvertising. It might behoove people to take their business to vendors with a good track record of not using ad networks that infect users. But keep in mind that sometimes these things slip into otherwise high-quality ad networks, so it’s a good idea to keep your software – especially OS, browsers and plug-ins – regularly updated, and have anti-malware suite including a firewall on your machines. Linux and OS X are not immune, and need to be protected with security software as well.”

In 2014, Spotify experienced a data breach. While it was a highly isolated incident – only one user’s data was accessed – the music giant nevertheless took the incident seriously.

It stated at the time: “We take these matters very seriously and as a general precaution will be asking certain Spotify users to re-enter their username and password to log in over the coming days.

“As an extra safety step, we are going to guide Android app users to upgrade over the next few days.”

Article by an editor for We Live Security

Samsung & Trade Me offer AI-powered shopping
The smartphone camera & AI-powered tech, Trade Me says, is a ‘glimpse into the future of shopping’.
Neill Blomkamp's 'Conviction' is a prequel to BioWare's Anthem
You may remember Neill Blomkamp’s name from such films as District 9, Chappie, and Elysium. If you’ve seen any of those films, the short teaser trailer will seem somewhat familiar to you.
Security flaw in Xiaomi electric scooters could have deadly consequences
An attacker could target a rider, and then cause the scooter to suddenly brake or accelerate.
617 million stolen records up for sale on dark web
It may not be the first time the databases have been offered for sale.
IBM’s Project Debater unable to out-debate human
At this incredible display of technology, the result was remarkably close but the human managed to pip the machine in this instance.
LPL to broadcast weekly programming on Sky Sports
Let’s Play Live (LPL) has now announced it will broadcast weekly programming for the rest of 2019 on the Sky Sports channel from Sky TV. 
When hackers get the munchies, they just steal McDonalds
What happens when hackers get the munchies? Apparently in Canada, they decide to put their ‘hamburglar’ gloves on and go after unwitting people who happen to use the McDonalds app.
The smart home tech that will be huge in 2019
For millennial home buyers, a generation for whom technology has been ever-present, smart systems are the features they value above everything else.