Security Management
Published on Security Management (http://www.securitymanagement.com)
Worm Burrows into Social Networking Web Sites
By Matthew Harwood
Created 03/04/2009 - 14:03



    
Wrap-Up?: 
No
Weight: 
0
Lead Headline?: 
No
Date: 
03/04/2009
By Line: 
By Matthew Harwood
Teaser: 

A worm preying on Facebook accounts in December is back with a vengeance, PCWorld.com reports. But this time, it's burrowing into other social networking Web sites, including Myspace, Friendster, LiveJournal and others.

A worm preying on Facebook accounts in December is back with a revenge, PCWorld.com reports [1]. But this time, it's burrowing into other social networking Web sites, including Myspace, Friendster, LiveJournal and others.

The Koobface worm is again making the rounds on Facebook, said Jamz Yaneza, a research project manager with Trend Micro Inc. "But this is an improved version with some interesting functions," he said.

Like the variant that hit Facebook late last year [2] , the newest Koobface tries to dupe users into clicking on a link that's included in a message from a friend. Clicking on the link displays a fake error message claiming that Adobe System Inc.'s Flash is out of date, and prompts the user to download an update.

The update is nothing of the sort, but is instead an executable file that installs the Koobface worm.

The Koobface worm then roots through the compromised computer, sniffing out cookies associated with ten social networking sites, stealing their logins, and then sending the malicious link to that site's users' friends.  Trend Micro advises anyone receiving suspicious messages with links not to click on them.

Times have been tough for Facebook lately. Last week, according to PCWorld, security researchers discovered another scam perpetrated on Facebook users.

The most recent [scam] sent messages to users claiming that friends had turned them in [3] for violating Facebook's terms of service; when people clicked on the included link, they downloaded an application that spammed all friends with a similar message and may have harvested information from each Facebook account as it did so.

Facebook is fighting back, reports Scientific American [4], by launching an application verification program that awards a verification badge graphic to safe applications. The program, however, is optional.

Related Resources: 

"Hoekstra Defends Iraq Twittering [5],"by Matthew Harwood, Daily Headlines, Feb. 11, 2009

"Cybercrime Trends Will Worsen in 2009, According to Forecasts [6]," by Matthew Harwood, Daily Headlines, Dec. 10, 2008

"U.S. Judge Hits Facebook Spammer with Massive Damages [7]," by Matthew Harwood, Daily Headlines, Nov. 26, 2008

Comments


Security Management is the award-winning publication of ASIS International, the preeminent international
organization for security professionals, with more than 38,000 members worldwide.

ASIS International, Inc. Worldwide Headquarters, 1625 Prince Street, Alexandria, Virginia 22314-2818 U.S.A.
703.519.6200 | fax 703.519.6299 | www.asisonline.org

ASIS

© 2013 Security Management
This site is protected by copyright and trade mark laws under U.S. and International law.
No part of this work may be reproduced without the written permission of Security Management.

Powered by: Phase2 Technology

Source URL: http://www.securitymanagement.com/news/worm-burrows-social-networking-web-sites-005302

Links:
[1] http://www.pcworld.com/article/160544/koobface_facebook_worm.html?tk=rss
[2] http://www.computerworld.com/action/article.do?command=viewArticleBasic&taxonomyName=knowledge_center&articleId=9122724
[3] http://blog.trendmicro.com/a-second-rogue-facebook-application-in-just-a-week/
[4] http://www.sciam.com/blog/60-second-science/post.cfm?id=new-koobface-worm-lets-hackers-play-2009-03-03
[5] http://www.securitymanagement.com/../../../../../../news/hoekstra-defends-iraq-twittering-005203
[6] http://www.securitymanagement.com/../../../../../../news/cybercrime-trends-will-worsen-2009-according-forecasts-004969
[7] http://www.securitymanagement.com/../../../../../../news/u-s-judge-hits-facebook-spammer-massive-damages-004952