Advertisement
Promo

Security threats Toolkit

Facebook worm exploits Google's reputation

Robert Vamosi CNET News

Published: 30 Oct 2008 10:42 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

For most Facebook users, it is common to receive a message from a friend urging them to visit a page containing a video.

However, one video making the rounds appears on a Google page and will not play unless a new codec is downloaded and installed. The link provided on the Google page is not a video link, according to researchers at Fortinet, but a link to a Trojan horse hosted on yet another server.

Guillaume Lovet, senior manager of Fortinet's security research team, told ZDNet UK sister site CNET News.com that Google sites were chosen because they have a good reputation and are unlikely to be blocked by spam or phishing filters. The Google page does not actually host the malware, only a link that connects the user with the malware host site.

In order to achieve this, the attackers had to register their own Google Reader accounts either by themselves or through automated methods using phishing sites or so-called Captcha solvers. The Google pages exist only to lead visitors to malicious sites.

For example, clicking the video takes the visitor to a 'player' on a non-Google page where a message about a missing codec is displayed. Unsuspecting viewers might be tempted to download it. The codec is actually a Trojan, Lovet said.

He said the Trojan being used in this attack is a downloader that includes Browser Helper Objects related to fake security software, or 'scareware'. The scenario here is that users will see a virus warning on their computer, then a prompt that asks if they want to purchase some security product to remove the malware from the PC. The criminals take the users' money, but the computer remains infected (if it was infected at all).

Lovet said the downloader currently does not include a copy of the worm. The only way at the moment to get infected is via the Facebook messages. He said he suspects the reason is that the attackers might try to sell the messages from Facebook to others, so they can spread their own malware.

A Google representative said: "Google works actively to detect and remove accounts that serve or link to malware. We're investigating reports we've received on this issue and are committed to shutting down any accounts that violate our guidelines."


 
Researchers at Fortinet said this video cannot be viewed because it is really a Trojan horse
 

 
Fortinet said the lack of definite articles indicates that the dialogue box originates from a Slavic country
 

Credit: Facebook worm feeds off Google's reputation from CNET News

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
5 out of 5 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:







Video icon

Video

Sentry Posts Blog

Malicious Mobile Apps a Growing Concer...

Malicious Mobile Apps a Growing Concern Author: Eric Everson, MBA, MSIT-SE The phrase “mobile security” does not usually mean much to anyone, until of course they encounter their... More

Post a comment

Malicious Mobile Code: What You Need t...

Malicious Mobile Code: What You Need to Know. Author: Eric Everson, MBA, MSIT-SE The thought of someone hacking into your mobile phone to steal your personal data added to the growing... More

1 comment

Bletchley Park calls for operators for...

The home of World War II codebreaking has called for engineers to operate an electro-mechanical machine developed by mathematician Alan Turing. The Turing Bombe was a brute-force... More

2 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters