::Trend Micro Threat Resource Center::

18 July 2009

Koobface Turns the Other Cheek

Twitter's in the news again.

There has been many reports of yet another variant of Koobface doing the rounds through Twitter. The tweets doing the rounds contain the following messages:
  • My home video :)
  • Watch my new private video! LOL :)
  • michaeljackson' testament on youtube
Looking around for some of the hacked twitter accounts, I found a few unfortunate souls whose accounts have been hijacked to spread this malware.

Here's one example I have found below. Some of the TinyURLs are pointing to the AdultFriendFinder Web site; the one below is not responding but appears to be active.

Other URLs are directing users to a fake video Web site that contains the usual Codec-type social engineering trick to lure users into downloading and running the file.

Symantec detects this as W32.Koobface.C. The threat that it drops is detected as Antivirus2008. Given the redirects chosen by the attacker and also the threat that it drops, clearly the makers of Koobface are in the business of making money.

Twitter has taken action and suspended accounts that have been infected.

To prevent your computer from becoming infected, be wary when clicking any links you receive in a tweet, even from your friends as this worm uses social engineering techniques in an attempt to infect your computer; that is once a user is infected it will send links to their followers and hence the link comes from someone you know.

Make sure that you also regularly update your anti-virus security software to catch the latest threats. Alternatively, you can check back here regularly for new updates. =)

Source