CyberInsecure.com

Daily cyber threats and internet security news: network security, online safety and latest security alerts
July 12th, 2009

Twitter Micro-blogging Compromised Accounts Spread Koobface Worm

The Koobface worm, which previously infected users of Facebook and MySpace, is spreading among users of micro-blogging website Twitter.

The scale of the attack is unclear but serious enough for Twitter to issue a warning on Friday morning, via the service’s status page:

Some users’ PCs have been infected with a variant of the Koobface malware. This malware sends bogus tweets when the user logs into Twitter.

We are currently suspending all accounts that we detect sending such bogus tweets. If we suspend your account, we will send you an email notifying you of the suspension. This email also includes tips for removing the malware from your PC.

Koobface-related activity has been detected on Twitter before, but the latest assault has provoked a more concerted response from the micro-blogging service, including plans to temporarily suspend compromised accounts.

Accounts accessed from compromised PCs inject rogue updates into a Twitter stream, supposedly containing a link to a video but actually pointing towards one of around 20 sites loaded with exploit code that poses as a video codec. Windows users who follow this links and install the “codec” wind up getting infected with Koobface, re-starting the whole infection cycle.

Some messages that point to exploit sites promise “michaeljackson’ testament on youtube” while others refer to “My home video :)”, Sophos reports, adding that users should avoid following malvertised links.

Panda Security reports that attempts to install rogue anti-virus (scareware) packages onto compromised machines are made, strongly suggesting that the attack is financially motivated.

Credit: The Register

Share this item with others:

More on CyberInsecure:
  • Compromised Twitter Accounts Spread Links to Malware Downloads
  • Twitter Users Hit Once Again, This Time With Rogue Anti-virus Scam
  • Old Facebook Worm Using New Ways To Spread By Abusing Google Reader And Picasa Websites
  • Twitter Grader Service Hacked, Thousands Of Unauthorized Tweets Posted From User Accounts
  • Warez Backdoor Allowed Hackers To Steal Twitter Passwords

  • If you found this information useful, consider linking to it from your own website.
    Just copy and paste the code below into your website (Ctrl+C to copy)
    It will look like this: Twitter Micro-blogging Compromised Accounts Spread Koobface Worm

    Leave a Reply

    Comments with unsolicited links to other resources will be marked as spam. DO NOT leave links in comments. Please leave your real email, it wont be published.

    *
    To prove you’re a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.