News Blog

Dec 5, 2008 03:27 PM in Technology | 16 comments

OMG, 'Koobface' worm gets up in the grill of Facebook and MySpace fans

By Larry Greenemeier

 
e-mail print comment

The "Koobface" software worm tormenting Facebook and MySpace users is still going strong, prompting them to download bogus software that infects their computers, sends spam out to their friends and allows hackers to redirect their Web searches.

The worm is activated when a person logs into his or her Facebook or MySpace account, creating and sending spam messages to listed friends via the Facebook or MySpace sites. The messages and comments include sophisticated fare such as "Paris Hilton Tosses Dwarf On The Street" and "My friend catched [sic] you on hidden cam" as well as a purported link to a video of the advertised content, according to security software maker Kaspersky Lab, based in Woburn, Mass. Clicking on that link delivers a message telling the user to download the latest version of Flash Player.

Instead of getting the latest player, though, the user gets software that spies on their actions, scanning all HTTP traffic, "in particular looking for traffic to Google, Yahoo!, MSN, and Live.com for the purpose of hijacking search results," Craig Schmugar, a security researcher for antivirus maker McAfee, Inc., wrote earlier this week on his blog. Translation: the Web traffic is diverted to other Web sties to pad their traffic results.

The outbreak has prompted a discussion thread of 194 Facebook users, since August 24, relating their experiences with Koobface. A user named Erin today posted to the thread stating that she was hit by the worm, "and I am HORRIFIED! It says something about seeing you posing naked and has some geocities link..."

User "Dale" described how the worm works. He wrote that he received a message from a Facebook friend saying, "I saw this video of you etc. It diverted me to a site that looked like youtube. It then stated my video player was out of date and to upgrade it. The moment I did and installed the file, FB began automatically sending messgaes [sic] to my contacts before my eyes."

Kaspersky in July reported having found two variants of the Koobface worm, Net-Worm.Win32.Koobface.a. and Net-Worm.Win32.Koobface.b, which attack MySpace and Facebook, respectively. The threat, Kaspersky reported, was that the worm could unleash malicious software that allowed a hacker to take remote control of your PC, turning it into a "zombie" and using it as a launching point to attack other computers.

Facebook says on its site that it is helping users deal with Koobface and phishing sites.  Its advice: that users scan their computer for viruses and reset their passwords if their Facebook accounts were recently used to spit out spam.

Facebook rep Barry Schnitt told CNET that "only a very small percentage of Facebook users have been affected" and that the company is  updating security to limit damage and block future breaches.

This attack comes just weeks after a federal court ordered Canadian spammer Adam Guerbuez to pay Facebook $873 million for falsely obtaining login information for Facebook users and then sending spam to those users' friends.

©iStockphoto.com

Read More About: MySpace, Facebook, Google, hack, Microsoft, worm

Share
Propeller    Digg!  Reddit delicious  Fark 
Slashdot    RT @sciam OMG, 'Koobface' worm gets up in the grill of Facebook and MySpace fansTwitter Review it on NewsTrust 
sharebar end

You Might Also Like


Discuss This Article


Click here to submit your comment.

VIEW:

2,573 characters remaining
 
  Email me when someone responds to this discussion.
 

risk free issuefree gift

Sciam - cover Email:
Name:
Address:
Address 2:
City:
State:  
spacer



World Changing Ideas


Most Popular Blog Posts


Editor's Pick


Newsletter

Technology Newsletter

Get weekly coverage delivered to your inbox


 Podcasts

  • 60-Second Science     RSS  · iTunes Botoxed Face Impairs Bad Feelings
    click to enable

    Download

  • 60-Second Science     RSS  · iTunes Distracted Customers' Wait Times Fly
    click to enable

    Download





ADVERTISEMENT
 
 


Also on Scientific American


© 2010 Scientific American, a division of Nature America, Inc. All Rights Reserved.
ADVERTISEMENT