On TV.com: TOP 10 Shows CANCELED Too Soon
BNET Business Network:
BNET
TechRepublic
ZDNet

January 6th, 2009

Bogus LinkedIn profiles serving malware

Posted by Dancho Danchev @ 4:31 pm

Categories: Anti Virus, Browsers, Hackers, Malware, Passwords, Social Networking Applications, Web 2.0

Tags: Security, LinkedIn, SEO, Dancho Danchev

LinkedIn Bogus Profiles MalwareA currently active malware campaign is taking advantage of bogus LinkedIn profiles impersonating celebrities in an attempt to trick users into clicking on links serving bogus media players. LinkedIn is among the latest social networking services considered as a valuable asset in the arsenal of the blackhat SEO knowledgeable cybecriminal, simply because this approach works. For instance, Googling for “Keri Russell nude” or “Brooke Hogan Naked pics” you’ll notice that the bogus profiles have already been indexed by Google and are appearing within the first 5/10 search results.

This is a proven tactic for acquiring search engine traffic which was most recently used in the real-time syndication of hot Google Trends keywords and using them as bogus content for the automatically generated bogus profiles using Microsoft’s Live spaces.  Approximately 70 to 80 bogus LinkedIn profiles appear to been created within the past 24 hours, with LinkedIn’s staff already removing some of them.

LinkedIn Bogus Profiles MalwareUpon several redirections a malware dropper (TubePlayer.ver.6.20885.exe) is served currently detected by 10 AV vendors as TrojanDownloader:Win32/Renos.gen!BB. Overall, the malware campaign is thankfully not taking advantage of any client-side vulnerabilities for the time being, leaving it up to the end user’s vigilance — if any if we’re to exclude the most abused infection vector for 2008.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 9 Talkback(s)
RE: Bogus LinkedIn profiles serving malware
Nicely done, Dancho. Your post is almost two months old, and yet we continue to observe initial vtotal AV scanner detection rates of 3/36 for this family of downloaders. They just can't keep up.
T... (Read the rest)
Posted by: TF_kj Posted on: 02/28/09 You are currently: a Guest | | Terms of Use
WOT and Privacy concerns  Christian_<>< | 01/06/09
Sure!  MGP2 | 01/06/09
I forgot about that guy...  Christian_<>< | 01/06/09
RE: Bogus LinkedIn profiles serving malware  DotWhat | 01/07/09
RE: Bogus LinkedIn profiles serving malware  ianhendry | 01/07/09
RE: Bogus LinkedIn profiles serving malware  lilchores09 | 01/07/09
RE: Bogus LinkedIn profiles serving malware  NerdHerd007 | 01/08/09
I am confused as I can never  davebarnes | 01/28/09
RE: Bogus LinkedIn profiles serving malware  TF_kj | 02/28/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
Click Here

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads