Malicious Software Spreading Through Social Networking Sites

There is an active attack occuring on a number of popular social networking sites, such as Facebook, MySpace, Friendster and others.  Victims receive an invitation to view a video with a link attached to it.  When they click on the link, a message is displayed which states that they need an update for Adobe Flash Player and offering to install it for them.  The “update” is not actually and update at all.  If the victim allows the install to proceed, they get some form of malicious software instead.

The software is a worm named Koobface (Facebook with the words switched and book spelled backwards) and made its first appearance on Facebook in December 2008.  Apparently it is back and is quite active.  The worm will infect your web surfing and redirect you to hostile websites when attempting to reach Google, Yahoo or MSN Live.

To avoid the issue, be very careful about opening any links in emails or messages you get.  If you are prompted to install software unexpectedly, don’t do it.  Get your software updates directly from the vendors only, such as adobe.com, microsoft.com, etc.

For more info:
US Cert Advisory

Hack in the Box

Jason Wood
Latest posts by Jason Wood (see all)