On The Insider: Adrian Brody to Star in New 'Predator'
BNET Business Network:
BNET
TechRepublic
ZDNet

July 7th, 2009

Koobface worm joins the Twittersphere

Posted by Dancho Danchev @ 2:00 pm

Categories: Anti Virus, Botnets, Browsers, Facebook, Hackers, Malware, Passwords, Social Networking Applications, Web 2.0

Tags: Worm, Twitter, Koobface, Cyberthreats, Viruses And Worms, Security, Dancho Danchev

Cybercriminals are experimenting with a new feature introduced in one of the latest Koobface variants - the ability of the worm to hijack the Twitter accounts of infected users and post tweets in an attempt to infect their followers.

According to researchers from TrendMicro, once the infected user attempts to log into Twitter, Koobface hijacks the session and posts a tweet on behalf of the user.

Would this novel feature allow the worm to spread even more efficiently? It largely depends on whether or not they’d remove the beta label from it, and go mainstream with the feature.

For the time being, the pre-defined set of messages include the following: My home video :); michaeljackson’ testament on youtube and Watch my new private video! LOL :). Interestingly, upon obtaining real-time statistics from their experimental Twitter campaign, the results show close to a hundred users that came to their bogus video serving (W32.Koobface.A) site through Twitter.

Compared to the automatic spreading of the worm across Facebook where the process of the CAPTCHA challenge recognition was outsourced, in Twitter’s case the lack of reliable use registration process or any sort of CAPTCHA challenge, makes the abuse of the micro-blogging service incredibly easy to accomplish.

Has the worm’s growth rate changed over the past month? According to recently released statistics from Kaspersky Labs, June was the most active month for the Koobface gang in terms of the number of samples generated — 324 Koobface variants at the end of May 2009, to almost 1000 by the end of June 2009 — a tactic used to increase the average time of their campaigns until they get intercepted. Earlier this year, PandaLabs confirmed the growth rate once again indicating the group’s commitment.

For the time being, Koobface remains one of the most active social networking worms spreading across Facebook, Tagged, Friendster, MySpace, MyYearBook, Fubar.com, Hi5 and Bebo since 2008, and despite the variety of new features, the worm continues relying on social engineering tactics in order to spread.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 4 Talkback(s)
Technical Details
Attacks! Infects! Are just scarewords. HOW deos it do this. Buffer overflow or what. I'm getting tired of reading articles like this with no beef.
Win32/64 programmer.... (Read the rest)
Posted by: ZwFlushKey Posted on: 07/08/09 You are currently: a Guest | | Terms of Use
Yet again another Windows Vector  Dietrich T. Schmitz | 07/07/09
RE: Koobface worm joins the Twittersphere  gertruded | 07/08/09
RE: Koobface worm joins the Twittersphere  eiverson@... | 07/08/09
Technical Details  ZwFlushKey | 07/08/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline