Showing posts with label myspace. Show all posts
Showing posts with label myspace. Show all posts

Tuesday, March 3, 2009

New Koobface Variant Spreads In Facebook

Security company Trend Micro warns in its blog about new Koobface worm variant.

Facebook user may get a message that looks like it was coming from friend's Facebook account. The message contains friend's picture and name with a link to a video.

The link opens a spoofed version of YouTube site. In the centre of the site there's a message telling that user must install Adobe Flash Player Update.

By clicking install -button user won't get any Flash update. Instead of it Koobface worm's new variant (detected as WORM_KOOBFACE.AZ) is downloaded.

Facebook users are not the only group in danger. The worm searches for cookies created by the following sites first:

* facebook.com
* hi5.com
* friendster.com
* myyearbook.com
* myspace.com
* bebo.com
* tagged.com
* netlog.com
* fubar.com
* livejournal.com


Then it connects to a respective site using login credentials stored in the gathered cookies. It then searches for an infected user’s friends, who are then sent messages containing a link where a copy of the worm is downloaded. It also sends and receives information from an infected machine by connecting to several servers. This allows hackers to execute commands on the affected machine.

Users of mentioned social networking domains are advised to ignore described messages, and refrain from clicking links in unsolicited messages.

Saturday, August 2, 2008

Malware Spreads In Social Networking Services

Security company Kaspersky Lab warns about new worm named as Koobface which uses social networking services, Facebook and MySpace to spread itself. Thus far four different variants of the worm exist.

Koobface makes infected systems part of botnet which clients spread malware links using friends lists of MySpace & Facebook. "The messages and comments include texts such as Paris Hilton Tosses Dwarf On The Street; Examiners Caught Downloading Grades From The Internet; Hello; You must see it!!! LOL. My friend catched you on hidden cam; Is it really celebrity? Funny Moments and many others."

Links in messages guide user to site containing video clip. If the user tries to watch the clip (s)he's been shown a message that asks to get the latest version of Flash Player to be able to watch the clip. Instead of the latest version of Flash Player, a file named as codesetup.exe is downloaded to the victim machine. That file is actually Koobface worm.

“Unfortunately, users are very trusting of messages left by 'friends' on social networking sites. So the likelihood of a user clicking on a link like this is very high. At the beginning of 2008 we predicted that we'd see an increase in cybercriminals exploiting MySpace, Facebook and similar sites, and we're now seeing evidence of this. I'm sure that this is simply the first step, and that virus writers will continue to target these resources with increased intensity”, says Alexander Gostev, Senior Virus Analyst at Kaspersky Lab.