Categorized | Antivirus

Facebook photo album chat messages spreading worm

Photo albumA new variant of the Koobface worm was making the rounds today on Facebook. This is particularly bad news. Most of the Facebook scams we report on do not infect your computer with malware; they simply make money from getting people to fill out surveys and send spams to other Facebook users.

An alert Naked Security reader, George, sent us a tip that he had received a suspicious Facebook chat message from a friend asking him to view a photo album. George is an experienced computer professional and immediately thought it might be fraud.

It’s very likely that George’s friend was infected with Koobface, as this is a technique Koobface has used for quite some time to trick Facebook users. Koobface is known to use chat and messaging to spread on LinkedIn, Twitter, Bebo, Hi5, Myspace and nearly every other social network with a sizable user base.

The link from the chat pointed to an app.facebook.com/CENSORED link. Typically when you go to a Facebook app page it prompts you to add the application and grant it permission to post on your behalf or read your profile data. The scary part about this one is that it immediately prompts you to download a “FacebookPhotos#####.exe” file with no prompting or clicking required.
Facebook Koobface photo app
The screen reads “Photo has been moved. This photo has been moved to other location. To view this photo click View Photo.” If your computer has not already downloaded the malware, the “View Photo” button will download the malware for you.

It is really unfortunate that Facebook scams are moving back towards spreading malware. Fortunately, users of Sophos Anti-Virus had proactive protection from this threat with both our HIPS and suspicious file detection technologies. This malware is now identified by Sophos as W32/Koobface-BA.

While I was researching this malware and writing this blog, Facebook removed the malicious application from their service. There are likely many more applications like this one making the rounds, so, as always, beware of unusual messages from friends whether they are in email, on their walls, or in an instant message.

If you’re a Facebook user, I invite you to join our Facebook page, where we post all the latest security news and threats you need to watch out for. We also have a Facebook privacy guide explaining how to navigate the privacy settings, with recommended settings to control your profile.

For those of you who need to educate your users on how to safely use social media sites, you can download our free social media education toolkit.

Full story: Naked Security – Sophos

Related Posts

3 Responses to “Facebook photo album chat messages spreading worm”

  1. santana says:

    tengo un problema con una amiga que a toda hora me envia un msn, es un virus, pero no se que decirle para que lo elimine, que hago??, es algo asi como de una foto, creo que es un gusano koobface ayudemen gracias

  2. adrian says:

    yo tengo ese problema si alguien me puede ayudar se lo agradesco cada vez q abro el chat a todos los q tengo conectados se lo manda por favor necesito ayuda

  3. RCrush says:

    I’ve got the virus now. What do I do to remove it? The computer I got it on actually belongs to someone else, so the situation is GRAVE. Please give me some help! Thanks.

Trackbacks/Pingbacks


Security Status

Beware Facebook "Timeline" scams http://t.co/W5EW0cVv
4 months ago
Nigerian government (unknowingly) hosts phishing website http://t.co/uQd42ENw
4 months ago
PCMag Awards McAfee All Access its Editors’ Choice: SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today announced... http://t.co/FakV7Vd8
4 months ago
RT @mikko: I hadn't noticed Google Maps has added 3D models of buildings. Here's a (very accurate) view of F-Secure HQ in Helsinki http://t.co/IKfAZlak
4 months ago
North Koreans aren't known for their online presence. But others may be lured into clicking Kim Jong-Il 'videos' too http://t.co/yQOon6YT
4 months ago
How to Protect Your Professional Reputation on Facebook Timeline http://t.co/I4bcR2VN
4 months ago
This is pretty impressive from @Softpedia: Facebook scans 2 trillion link clicks and blocks 220 million posts each day http://t.co/vKsn9gNl
4 months ago
Need for integrated approach to security in industrial control systems - http://t.co/tPBCNOow with @PikeResearch
4 months ago
Some free-based music we play at work http://t.co/xu5agZfc
4 months ago
Japan’s cyber defense weapon: a virus. It includes quotes by @Luis_Corrons via @InfosecurityMag
4 months ago