Advertisement
Promo

Security threats Toolkit

Koobface virus lures Facebook users

Robert Vamosi CNET News

Published: 05 Dec 2008 12:12 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A worm responsible for sending Facebook users malicious code appears to be limited in nature, although the social-engineering attack may be used again, say experts.

Facebook representative Barry Schnitt said the worm isn't new; it dates back to August, although the variant that first appeared on Wednesday targets only Facebook users.

Craig Schmugar, threat researcher for McAfee Avert Labs, confirmed this to ZDNet UK's sister site, CNET News, and said that in general Koobface strikes only social-networking sites.

After receiving a message in their Facebook inbox announcing, "You look funny in this new video" or something similar, recipients are then invited to click on a provided link. Once on the video site, a message says an update of Flash is needed before the video can be displayed. The viewer is prompted to open a file called flash_player.exe.

Schmugar said the prompt for a new player should be a warning. "The messages you tend to get from these sites don't look quite right." For instance, IE will tell you where the update is coming from, and usually it is not an Adobe site.

Read this

Q&A
Q&A: Facebook and the price of user privacy

Aaron Greenspan warns that Facebook is sacrificing user privacy on the altar of hyper growth

Read more +

If the viewer approves the Flash installation, Koobface attempts to download a program called tinyproxy.exe. This loads a proxy server called Security Accounts Manager (SamSs) the next time the computer boots up. Koobface then listens to traffic on TCP port 9090 and proxies all outgoing HTTP traffic. For example, a search performed on Google, Yahoo, MSN or Live.com may be hijacked to other, lesser-known search sites.

Schmugar said this version of Koobface includes a bot-like component that could install other malicious apps at a later time.

Facebook's Schnitt said: "Only a very small percentage of Facebook users have been affected and we're working quickly to update our security systems to minimise any further impact, including resetting passwords on infected accounts, removing the spam messages and co-ordinating with third parties to remove redirects to malicious content elsewhere on the web."

Facebook has posted instructions on how to remove the infection.

McAfee's Schmugar said this attack is similar to email attacks 10 years ago, in that Koobface is using infected 'friends' lists, reminiscent of early mass-mailing worms. As was the recommendation then, he advises users not to open any unexpected email attachments, even if they are from someone you know.

Credit: Koobface virus hits Facebook from CNET News

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
22 out of 22 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Sentry Posts Blog

DNA details of innocent will be kept f...

The government has announced that it plans to keep innocent people's DNA details for up to six years. In response to a consultation it launched last December, the government said... More

5 comments

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters