Facebook Virus: Koobface Spreads via Messaging

by Jordan Yerman | December 5, 2008 at 07:36 am
1569 views | 1 Recommendation | 0 comments

Photos

bandit (Skype emoticon)

bandit (Skype emoticon)

see larger image

uploaded by Jordan Yerman

The Koobface virus is swarming Facebook, having been eliminated earlier this year from MySpace. The virus basically zombifies your account and turns it into a malware distribution device. And that's bad. I haven't yet found a reliable Koobface removal walkthrough, so it likely has to be done manually, which is never pretty. I'm sure, though, that a fix will be available soon.

Affected users are told to change their password so that the virus can no longer access their friend lists.

Here's he juice from Kapersky Labs:

Kaspersky Lab, a leading developer of secure content management systems, has detected two variants of a new worm, Net-Worm.Win32.Koobface.a. and Net-Worm.Win32.Koobface.b, which attack MySpace and Facebook respectively. As part of their malicious payload, the worms transform victim machines into zombie computers to form botnets.

The malicious code isn't exactly new (it started surfacing in August), but has now been altered to strike social networking websites only and is currently making the rounds on Facebook pretty quickly, it seems. The virus can spread fast because they travel through messages which appear to come from your friends.

The Koobface messages carry subject lines like "You look so funny on our new video" or something similar, and contain a link to a video site that appears to contain a movie clip.

Messages and comments on MySpace and Facebook include links to http://youtube.[skip].pl. If the user clicks on this link, s/he is redirected to http://youtube.[skip].ru, a site which purportedly contains a video clip

The virus will then direct the user to download a new video plugin, which (surprise, surprise) is malware.

The worm creates a range of commentaries to friends' accounts. Net-Worm.Win32.Koobface.b, which targets Facebook users, creates spam messages and sends them to the infected users' friends via the Facebook site. The messages and comments include texts such as Paris Hilton Tosses Dwarf On The Street; Examiners Caught Downloading Grades From The Internet; Hello; You must see it!!! LOL. My friend catched you on hidden cam; Is it really celebrity? Funny Moments and many others.
Be careful out there: don't trust messages with generic subject lines. Your real friends will forgive you if you miss out ona LOL video now and then- it's better to leave the malware out in the cold, where it belongs.

Advertisement

Comments (0)

This story was created over 3 months ago, the comment thread is now closed.

NowPublic on Facebook

What is NowPublic?

NowPublic lets people work together to cover news events around the world.

Find out more

Crowd Power

Anonymous
First Flagged at 12:34 PM, Dec 5, 2008 by Anonymous (not verified)
These members have powered this story:

Most Recommended Stories in Tech & Biz

Recommendations (1)

Most recently recommended by:
 

closeSign in to NowPublic

is reporting from