• On TechRepublic: FREE download: Social networking policy
September 8, 2008 4:04 PM PDT

Twitter page used to pass malware

by Robert Vamosi
  • Font size
  • Print
  • 2 comments

In this screenshot from Facetime, clicking the link for a photo album could get your computer infected.

(Credit: Facetime)

In yet another new way to infect people, criminal hackers are using a Twitter page, according to one security researcher.

In a blog, Chris Boyd, director of malware research for Facetime, explained how a Twitter page is being used to lure victims. To lend credibility to his discovery, the Twitter page lists 17 followers, however each appeared to be fraudulent. Boyd said Twitter had been notified.

The messages, written in Portuguese, attempt to get visitors to download a photo album. In order to view the album, you'll need to download a Flash update, which is really the infection files themselves. Boyd and his team have identified the infection as Orkon.

Once installed, the infected files do various things to the compromised desktop, such as attempt to gain your Orkut account log-in information, or displaying a browser image of a man identifying himself as the "Trickster."

Orkut has been targeted in the past. Here, the infection itself is not so interesting, as is use of Twitter as a vector. Boyd recommends that even if you don't use Orkut, if you see a Twitter page referencing an Orkut photo album, stay away.

As CNET's resident security expert, Robert Vamosi has been interviewed on the BBC, CNN, MSNBC, and other outlets to share his knowledge about the latest online threats and to offer advice on personal and corporate security. Listen to his podcast at securitybites.cnet.com or e-mail Robert with your questions and comments.
advertisement
Click Here
Recent posts from Security
Pub fined $13k for Wi-Fi copyright infringement
Tips for safe online shopping
Big changes in Security Starter Kit 2010
Confidential 9/11 pager messages disclosed
Microsoft warns of IE exploit code in the wild
Chrome OS security: 'Sandboxing' and auto updates
E-tailers snagged in marketing 'scam' blame customers
McAfee warns about '12 Scams of Christmas'
Add a Comment (Log in or register)
by Wookiee-1138 September 8, 2008 6:16 PM PDT
Even the best of us can fall for such tricks, but dang...

Do people really install with no questions asked?
Reply to this comment
by Harrison912 September 9, 2008 6:59 PM PDT
I use social sites to raise awareness for my safety and security products. I hope they catch these people. We all need a safe social experience!
Reply to this comment
advertisement

The browser battles go on and on

roundup From Firefox to IE and from Chrome to Opera and Safari, there's no sitting still for browser makers looking to keep their products fresh and competitive.

3G wireless still holds promise

The next generation of 4G wireless may get all the headlines, but advanced 3G technology will likely dominate services for the next few years.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right