• On GameSpot: Handheld Xbox coming...eventually.
March 2, 2009 12:05 PM PST

Facebook fights new Koobface worm, another rogue app

by Elinor Mills

Like flies to cow dung, rogue apps are swarming to Facebook.

The popular social-networking site has been hit by what's believed to be the fourth rogue app in a week or so and is investigating the spread of a new variant of the Koobface worm, according to security firm Trend Micro.

The Koobface worm spreads via a message from a Facebook friend that includes a link to what looks like a video, Rik Ferguson wrote on the Trend Micro blog.

This screenshot shows the fake YouTube Web site that the link leads to in the new variant of Koobface.

(Credit: Trend Micro)

The landing page displays the name and photo of the friend. Clicking the "install" button redirects to a download site for the file "setup.exe," which is the new variant of Koobface dubbed Worm_Koobface.az.

"Previous versions didn't have all these complexities and automation built in," Jamz Yaneza, a senior threat analyst and researcher at Trend Micro, said in an interview. "This new variant has a back end doing all the modifications."

Once the worm infects a computer it sends cookie information to a remote server, of which there are as many as 300 in the operation, he said. "Now you can use a third-party connection via the Facebook API," he said. The cookie information can include unencrypted log-in information, enabling attackers to masquerade as a legitimate Facebook user, Yaneza added.

The worm connects to a site using log-in credentials stored in the gathered cookies and sends messages to the friends of an infected user. It also sends and receives information from an infected machine by connecting to remote servers and allows attackers to execute commands on infected machines.

The worm is targeting users of other social-networking sites, including MySpace, Bebo, Friendster, hi5, MyYearbook, Tagged.com, Netlog, Fubar, and LiveJournal.com, Trend Micro said. An earlier version of Koobface hit Facebook .

Facebook spokesman Barry Schnitt said the company is investigating the new variant of Koobface.

Meanwhile, another rogue application is spreading that displays a message that says "Closing Down! You reported them for violating their terms and policies," Trend Micro said. Once the application is installed it spams itself to a victim's friends.

The news comes after word of Facebook swatting down a similar rogue app late last week and another one a few days before that.

"It seems that Facebook as an attack platform may be coming of age," Ferguson wrote in an e-mail.

Facebook implemented an app verification policy late last year after getting criticized for not vetting its apps enough. But the security and privacy "seal of approval" policy is voluntary.

Yaneza said it should be compulsory for all Facebook apps, like Apple vets all the iPhone apps.

Facebook's Schnitt said the company is looking into the app and would disable it if it turns out to be deceptive or malicious.

"It is important to note that we've built security into Facebook Platform by preventing any app, including the rare malicious app, from accessing sensitive information like contact info," he said in an e-mail.

"Only a small percentage of Facebook users have been affected by security issues, including Koobface," Schnitt said. "We're updating our security systems to minimize further impact, including resetting passwords on infected accounts and identifying and deleting malicious content sent by the virus. We've posted a note about this on our security page to educate users.

In a separate e-mail, Schnitt added: "Worms like koobface update relatively frequently. Koobface is on its 28th version of the binary since it first started attacking social networking sites last summer. The difference is essentially in the webpages hosting it - the landing page where users are tricked into downloading a fake update that installs the virus. Users should be very suspicious of strange messages from friends and should always confirm a software update is necessary through the vendor's website (Adobe.com, etc...) before downloading it from a third party."

Elinor Mills covers Internet security and privacy. She joined CNET News in 2005 after working as a foreign correspondent for Reuters in Portugal and writing for The Industry Standard, the IDG News Service, and the Associated Press. E-mail Elinor.
advertisement
Click here!
Recent posts from Security
Panda's Cloud Antivirus leaves beta behind
Apple plugs holes for domain spoofing, other attacks
Microsoft launches Forefront Protection 2010
'60 Minutes'--Cyberwar: Sabotaging the system
Microsoft to fix holes in Windows, Office
Google privacy controls: Most people won't care
Zero-day flaw found in Web encryption
Mac Game: Art project or malware?
Add a Comment (Log in or register) (6 Comments)
  • prev
  • 1
  • next
by loose_screw March 2, 2009 12:35 PM PST
Again? Good grief. Facebook should kill most 3rd party apps since they're useless anyway.
Reply to this comment
by ShariCooper March 3, 2009 10:58 AM PST
OK my son did this last night on my IMac how do I fix??? is there a fix?
Reply to this comment
by CapitalVA March 4, 2009 12:29 PM PST
Try this fix for the Koobface worm: http://www.facebook.com/security

Geri Lafferty
Capital Virtual Assistance
www.capitalva.com
by Harrison912 March 3, 2009 11:09 AM PST
I've been on FaceBook for some time now to socially market my safety and security web site as well as raise awareness for it products through interaction with friends there and I've found FaceBook to be very responsive when security issues arise. In my industry, we like to catch and punish the bad guys but I think when it comes to computer security, it's easier said than done. Thanks, Elinor, for this information.
Reply to this comment
by darthstupid March 3, 2009 8:50 PM PST
Totally agreed loose_screw.
Reply to this comment
by carol532 March 4, 2009 4:46 PM PST
Social networks such as MySpace and Facebook appear to be very concerned about the safety of their members which is evident from reports I have read inclusive of this one. Unfortunately, I think newforums such as TOPIX should be better moderated. When posting in that site several months ago, my computer was hacked which not only disabled it, but revealed my identity to someone I would have never wanted to be known to.

People in the political forums specifically in TOPIX link like crazy to each other in their posts - which is how my computer was hacked. There are also HUNDREDS of moderators/editors on TOPIX who have too much control over the individual threads and have the ability to read your "footprints" when you post which creates even more vulnerability for their contributors. Cybercriminals can use a proxy server and pose as several registered or unregistered contributors.

Investigators of cybercrime SHOULD be looking into these very large and very public newsforums very closely.

Unless something is actually stolen from you - there is NO crime committed and therefore there will be no real investigation. I no longer contribute to TOPIX as I am too afraid to, but since last I looked, my suspected hacker(s) still post there - still linking away . . . . .
Reply to this comment
(6 Comments)
  • prev
  • 1
  • next
advertisement

After 5 years, Firefox faces new challenges

Mozilla helped reshape the Web since releasing Firefox 1.0 five years ago. Now it's got a reawakened Microsoft and Google Chrome to reckon with.

There's a map for that: GPS or smartphone?

Almost every handset comes with mapping software these days, but standalone GPS devices are becoming more affordable than ever.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right