Koobface Worm Attacks Facebook and MySpace Users

ZulaZuza By ZulaZuza in Computer Security | 865 views
Rate it:
1 Star2 Stars3 Stars4 Stars5 Stars (2 votes, average: 5.00 out of 5)
Loading ... Loading ...

The Koobface worm has been circulating since August but in recent weeks variants, known as Worm.KoobFace.A and Worm.KoobFace.B, have increasingly spread via spam messages on social networking websites MySpace and Facebook.

Koobface worm creates deceptive spam messages and sends them to an infected users’ list of friends through Facebook’s messaging system. Koobface is able to send spam messages to a user’s Facebook friends by downloading a file called tinyproxy.exe which installs a program called “Security Accounts Manager.” The program tracks the cookies on a user’s computer, detects the user’s friends list, and sends them spam messages. Messages from the Koobface worm include the following subject headers: “You must see it!!! LOL,” “Look you were filmed all naked!,” “You look just awesome in this movie,” or “Paris Hilton Tosses Dwarf On The Street.” Koobface exploits social networks like Facebook because it knows that users will most likely not question a message that appears to come from one of their friends on Facebook.

If a Facebook user clicks on the link provided by the spam message, he/she is sent to a video website meant to mimic YouTube which will pop-up a message that tells the user that their Flash Player is outdated and to download the latest version to view a video. The download file is really the Koobface worm disguised as an executable file called flash_player.exe.

Koobface, with the help of the “Security Accounts Manager,” monitors TCP port 9090 and proxies HTTP traffic from an infected computer to hijack search results from search engines like Google, MSN, and Yahoo.

Facebook spokesperson Barry Schnitt said, “Only a very small percentage of Facebook users have been affected and we’re working quickly to update our security systems to minimize any further impact, including resetting passwords on infected accounts, removing the spam messages, and coordinating with third parties to remove redirects to malicious content elsewhere on the Web.” Facebook has posted security steps to deal with the Koobface issue and other threats on its Security page.

To reduce the risk of infection, it is advisable to use caution when opening messages in Facebook. Facebook users should not open unexpected e-mail attachments or download files from suspicious or untrustworthy sources.

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Furl
  • StumbleUpon
  • Technorati
  • YahooMyWeb
This entry was posted on 12/5/08 and is filed under Computer Security. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Comment

Note: Abusive comments are not allowed. Please do not post comments regarding technical support issues. ESG customers that have issues with SpyHunter should open a customer support ticket.

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word

Poll

How much money have you spent trying to rid your PC of spyware?
View Results
Follow Us on Twitter

Archives

Home Sitemap RSS Feed Privacy Policy End User License Agreement Copyright 2003-2010. Enigma Software Group USA, LLC. All Rights Reserved.