Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

January 14th, 2011, 18:37 GMT · By

New Koobface Campaign Spotted on Facebook

SHARE:

Adjust text size:


New Koobface variant making the rounds on Facebook
Enlarge picture
Security researchers from Web and email security provider Websense have spotted a new private message spam campaign on Facebook distributing the notorious Koobface worm.

The messages have a subject of "Check out the movies wsith yor ass in it" and advertise a link that leads to a bit.ly shortened URL through Facebook's open redirector.

Facebook's redirect script, through which all external links are normally passed, has been increasingly abused lately to bypass spam filters.

The spammed link takes users through a series of redirects that check if they come from facebook.com. If they are, they land on the attack page, if not, on Google News Canada.

In traditional Koobface style, the landing page displays a fake video player with a message reading "This content requires Adobe Flash Player 10.37. Would you like to install it now?"

This "required Flash update" social engineering trick is one the Koobface authors pretty much pioneered and used on a large scale. It has since been picked up by many other cybercriminals.

Pressing the Install button to get the alleged update, serves a Koobface variant currently detected by only 16 out of 43 antivirus engines on Virus Total.

Koobface is the father of all social networking worms and dates back to 2007, which makes it one of the longest running computer worms in history.

The threat has separate versions for multiple social networks including, MySpace, Twitter, hi5, Bebo or Friendster, but the worm is most active on Facebook.

Nick Bilogorskiy, malware researcher at Facebook, estimated last year that the Koobface authors earned on average $35,000 per week in 2009, which adds up to $1.8 million for the entire year.

This explains why the gang tries to keep the botnet alive with constant improvements to the malware and new social engineering techniques.

TELL US WHAT YOU THINK:

1,492 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Worm Uses Photo Lure to Spread via Facebook Chat

Facebook Knows Who the Koobace Authors Are

New Koobface Variant Installs Highly Invasive Rogueware

New Koobface Campaign Spotted on Facebook

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM