Danger for Facebook Users: Kaspersky Lab Warns About Koobface

Koobface command-and-control servers double within 48 hours. Simple measures protect against infection

Archive notice: This article was originally published on March 12, 2010. Links and embedded videos are preserved as part of the historical record.

Kaspersky Lab warns of attacks by the Koobface malware – a worm that attacks social networks such as Facebook and MySpace and misuses infected legitimate websites as proxies (effectively “cover addresses”; [1]) for its most important command-and-control servers (C&C servers). Cybercriminals can use the C&C servers to control Koobface-infected computers remotely – for example, misusing them as part of a botnet. Following the drastic rise in Koobface variants between May and June 2009 [2], the increase in C&C servers shows that the Koobface gang continually maintains and optimises its botnet.

During the past two weeks, Kaspersky experts discovered that numerous Koobface C&C servers were shut down or cleaned – an average of three times a day. The result: first, the number of Koobface C&C servers fell from 107 to 71; it then rose to 142 within 48 hours.

“The latest events show us that cybercriminals regularly maintain, service and, where necessary, optimise the infrastructures they have created on the internet through malware such as Koobface,” says Stefan Tanase, Senior Regional Researcher at Kaspersky Lab. “If the number of C&C servers falls, for example, new ones are installed immediately. The total number of Koobface C&C servers must not fall too sharply, as otherwise control of the botnet could be lost. The figure always fluctuates around 100; at that level, the Koobface gangsters seem to sit back. They also ensure that the servers are distributed around the world to make tracking them more difficult. However, most Koobface C&C servers are currently located in the USA.”

Koobface spreads, among other methods, through existing user accounts and their friend lists on social networks by sending comments and messages containing a link, for example to a fake YouTube page, and asking users to download a current version of Flash Player. Instead of the new media player, however, Koobface lands on the victims’ computer. Once a user is infected, worm-contaminated messages are also sent to friends through that person’s account.

Following a few simple rules helps social-network users in particular keep their computer free of Koobface:

* Be careful when opening links sent in suspicious messages, even if the apparent sender is a friend.

* When browsing, always use the latest version of your internet browser, including the newest updates.

* Disclose as little personal information as possible. Avoid providing your address, telephone number and other private details.

* Keep your antivirus software up to date with the latest updates. This protects you against all new threats.