About Me

Craig Schmugar

Craig Schmugar

Read More

Feeds & Podcasts

Blogs

Meet the Bloggers

Archive

Tags

#SecChat $1 million guarantee 12 Scams of Christmas access to live fraud resolution agents Acquisition Alex Thurber Android antivirus Apple botnet Channel Partners cloud security Compliance Consumer counter identity theft credit card fraud and protection credit fraud alerts credit monitoring credit monitoring and resolution critical infrastructure Cyber Security Mom cyberbullying Cybercrime cybermom data breach data center data center security Data Protection Dave DeWalt DLP Email & Web Security embedded encryption Endpoint Protection enterprise facebook fake anti-virus software Family Safety Friday Security Highlights global threat intelligence google government Hacktivism how to talk to kids how to talk to teens identity fraud identity fraud scams identity protection identity protection $1 million guarantee identity protection fraud identity protection surveillance identity surveillance identity theft identity theft expert identity theft fraud identity theft protection identity theft protection product Identity thieves and cybercriminals intel iphone kids online behavior lost wallet protection malware McAfee McAfee Channel McAfee Family Protection McAfee Identity Protection McAfee Initiative to Fight Cybercrime McAfee Labs McAfee security products Mid-Market Mobile mobile malware mobile security monitor credit and personal information Network Security online personal data protection online safety Operation Aurora PCI personal identity theft fraud personal information loss personal information protection phishing privacy proactive identity protection proactive identity surveillance Public Sector restore credit and personal identity Risk and Compliance scam scams scareware security smartphones social media social networking social networks spam Stuxnet twitter vulnerability Web 2.0 work with victim restore identity

Koobface Going for Broke?

Friday, July 16, 2010 at 12:40pm by Craig Schmugar
Craig Schmugar

The Koobface worm has been one of the top malicious threats to Facebook users since 2008. Like most threats, Koobface has morphed over time, adding and changing malicious payloads, while maintaining the ability to propagate, or spread, from one system to another.

A common misconception is that viruses often delete files or cause irrevocable system damage. There certainly are a number of viruses in this category, but the majority aim to go unnoticed. A damaged system is unable to spread the virus to other victims, while a quietly infected system can be used indefinitely to spread the virus. Furthermore, systems that show obvious signs of infection are more likely to result in the owners’ seeking remediation.

Historically Koobface has varied, sometimes installing password-stealing malware in the background and other times prompting users to enter CAPTCHAs.

Several weeks ago Koobface added DNS hijacking functionality that blocks access to security sites, tipping users off to the fact that something might be wrong with their systems. Since then the authors have taken a giant leap toward invasiveness with the installation of a fake anti-virus Trojan.

About 10 minutes after the initial infection, users may see the typically fake scanning windows and infection alerts:

It’s all downhill from here. The Trojan acts as an HTTP proxy and configures Internet Explorer to route HTTP requests through that proxy, which blocks access to everything but the site to purchase the fake AV software and a handful of porn sites. This payload even blocks another component of Koobface that is designed to display pop-ups and redirect search result links, leaving the user with Koobface created pop-ups that display fake error messages.

The malware also blocks almost every executable from running, making the system pretty much useless for most users.

It’s unclear how this self-competing threat came about, but the crippling payload is delivered from the same domains as the other Koobface components. Perhaps the gang is going for one last big payoff, trying to get as many users as possible to pay $49.95-$69.95 to register “AV Security Suite.” It’s more likely, however, that the Koobface gang has such confidence in their ability to infect new users that they aren’t worried about leveraging the current infection base to propagate their threats.

The vast majority of Koobface infections come from users who “choose” to run the virus. They are tricked by the social engineering used by the authors, who prey on people’s curiosity and thirst to view some enticing video.

Bookmark and Share

Submit your own comments / message for this post

Your email is never published nor shared. Required fields are marked *

 

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Comments (0)