On The Insider: Avril Lavigne Files for Divorce
BNET Business Network:
BNET
TechRepublic
ZDNet

July 31st, 2008

Web worms squirm through Facebook, MySpace

Posted by Ryan Naraine @ 4:31 pm

Categories: Adobe, Anti Virus, Arbitrary Code Execution, Botnets, Browsers, Exploit code, Facebook, Flash, Hackers, Malware, Passwords, Phishing, Social Networking Applications, Spam and Phishing, Viruses and Worms, Vulnerability research

Tags: Web, Facebook, Kaspersky Lab, Network, Macromedia Flash Player, Social Engineering, Worm, MySpace, Victim Machine, Cyberthreats

Cross-network worm squirms through Facebook, MySpaceMy colleagues at Kaspersky Lab (see disclosure) have intercepted two new worms squirming through MySpace and Facebook, using social engineering lures to plant malware on Windows systems.

The worms propagate via the comments features on the two popular social networks, using video lures and fake Flash Player downloads to trick end users into installing malicious executables.

As part of their malicious payload, the worms transform victim machines into zombie computers to form botnets. Even though the worms are currently only infecting MySpace and Facebook users, Kaspersky Lab analysts are warning users that the worms are designed to upload additional malicious modules with other functionality via the Internet. It is highly probable that victim machines will not only be used for spreading links via these social networking sites, but the botnets will also be used for other malicious purposes.

Some of the messages and comments posted to the social network sites include:

  • Paris Hilton Tosses Dwarf On The Street
  • Examiners Caught Downloading Grades From The Internet
  • Hello; You must see it!!! LOL. My friend catched you on hidden cam
  • Is it really celebrity? Funny Moments and many others.

The messages and comments include links to a fake YouTube-like site. Clicking on the link redirects the targer to another YouTube clone fitted with a note to download the latest version of Adobe’s Flash Player.

Web worms squirm through Facebook, MySpace

However, instead of the latest version of Flash Player, a file called codesetup.exe is downloaded to the victim machine; this file is also a network worm.  Kaspersky said its security suite detected the threats proactively and signatures were added to the database on July 31, 2008.

The use of Flash Player downloads as the social engineering enticement is interesting. For the most part, malicious hackers have used fake codecs alongside video lures but, since Flash Player downloads are a normal part of the Web surfing experience, the likelihood that end users fall for this latest trick is rather high.

As usual, if you’re on a social networking site, you are encouraged to pay close attention to executables downloaded to Windows machines, keep your machine fully patched and run updated anti-malware software.

* Image source: Gastev’s Flickr photostream (Creative Commons 2.0)

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 39 Talkback(s)
Huh?!
I keep getting spams in my inbox with very similar titles to those mentioned above. They immediately set off my mental "this is fishy" alert as no-one with two brain cells to rub together writes that ... (Read the rest)
Posted by: tahrey Posted on: 11/07/08 You are currently: a Guest | | Terms of Use
Facebook and Myspace Worm & Viruses  arc-djt@... | 08/01/08
Good luck...  Wolfie2K3 | 08/01/08
Good luck ?????????????  ciere24_@... | 08/04/08
As absurd as a may sound  alaniane@... | 08/04/08
They COULD help. If they cared.  ssaxton@... | 08/04/08
RE: They could help. If they cared.  bfilipiak@... | 08/06/08
make the kids pay for not listening to you  bzim05@... | 08/05/08
True  Cavke | 08/18/08
Freudian Slip?  Leslie The Computer Lady | 08/05/08
DOS is dead...  Wolfie2K3 | 08/01/08
DOS lives on in many ways.  draciron@... | 08/04/08
Thank God for DOS  dolls4his | 08/04/08
DOS is important  bzim05@... | 08/05/08
RE: Web worms squirm through Facebook, MySpace  twaynesdomain | 08/01/08
RE: Web worms squirm through Facebook, MySpace  precisonline | 08/04/08
RE: Web worms squirm through Facebook  banner@... | 08/05/08
RE: Web worms squirm through Facebook, MySpace  ninjoe1@... | 08/04/08
Problem is that you have to extradite many of them first  alaniane@... | 08/04/08
Another reason to use Linux for Web activities.  joe.smetona@... | 08/04/08
RE: Web worms squirm through Facebook, MySpace  lektrikpuke@... | 08/04/08
Block Flash  mswift@... | 08/04/08
Not a Flash problem  dazweeja | 08/04/08
RE: Web worms squirm through Facebook, MySpace  seanick | 08/04/08
RE: Web worms squirm through Facebook, MySpace  kc117mx | 08/04/08
RE: Web worms squirm through Facebook, MySpace  jeremy@... | 08/05/08
I Disagree.  joe.smetona@... | 08/05/08
Yes, but...  bzim05@... | 08/05/08
Cleaning Computers can be frustrating.  joe.smetona@... | 08/05/08
RE: Web worms squirm through Facebook, MySpace  Greenknight_z | 08/05/08
RE: Web worms squirm through Facebook, MySpace  lethal9x | 08/06/08
RE: Web worms squirm through Facebook, MySpace  rlcjr@... | 08/06/08
RE: Web worms squirm through Facebook, MySpace  Kopiko | 08/13/08
RE: Web worms squirm through Facebook, MySpace  Carly1000 | 08/20/08
try this  megamanx | 08/28/08
RE: Web worms squirm through Facebook, MySpace  Oenc | 09/05/08
RE: Web worms squirm through Facebook, MySpace  dinosoft@... | 09/25/08
RE: Web worms squirm through Facebook, MySpace  dinosoft@... | 09/25/08
RE: Web worms squirm through Facebook, MySpace  samaldis | 10/30/08
Huh?!  tahrey | 11/07/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Meet Doc