Twitter suspends accounts of users with infected computers

The site is fighting back against the Koobface virus, which is hijacking user accounts to ensnare new victims

Twitter is suspending the accounts of some users whose computers have fallen victim to a well-known piece of malicious software that has targeted other sites such as Facebook and MySpace.

The malware, Koobface, is designed to spread itself by checking to see if person is logged into a social network. It will then post fraudulent messages on the person's Twitter account trying to entice friends to click the link, which then leads to a malicious Web site that tries to infect the PC.

The popular microblogging service has had a strong impact as a new communication platform, such as providing on-the-ground insight from participants in the recent protests over the presidential election in Iran. But it is also being targeted by fraudsters and hackers, who using it as a way to infect people's PCs with malicious software.

Twitter is the latest site to be targeted by a Koobface variant, said Rik Ferguson, senior security advisor for Trend Micro. Other sites have included Bebo, Hi5, Friendster and LiveJournal, according to the U.S. Computer Emergency Readiness Team.

"Koobface has a long, inglorious history and has been relatively successful at infecting machines," Ferguson said.

At least a couple hundred accounts have been infected by Koobface's latest efforts, according to Ryan Flores, an advanced threats researcher, writing on Trend's blog. When it made its first appearance a couple of weeks ago on Twitter, Koobface was just sending out three shortened URLs (Uniform Resource Locators) leading to malware. Flores wrote that Koobface is sending out more bad links this time around.

The use of URL shortening services on Twitter have made it difficult for people to tell what Web site they'll end up at, Ferguson said. However, Twitter tools such as TweetDeck will show the full URL, which can help make people make a better security judgement, he said.

Some of Koobface's bad links have advertised, for example, videos of Michael Jackson, where the malware writers are trying to pique people's interest in current news events, said Graham Cluley, senior technology consultant for Sophos. If a person followed the link, it would lead to a Web site asking the user to download an upgrade for their Flash multimedia players but is actually Koobface, he said.

But Twitter has been fairly quick at shutting down accounts of people who are infected with Koobface and resetting their passwords, Cluley said.

Malware has also spread on Twitter via fake accounts that have been registered using automated tools. Ferguson said Twitter could somewhat guard against that by sending a verification link to an e-mail address during registration, making it more difficult to register dummy accounts en masse.

"That's real low-hanging fruit for them to address," Ferguson said.

Koobface gets instructions from a command-and-control server, which tells the malware which messages to send out. Koobface is dangerous on other levels, however, as it can also steal data from a PC or download other malware.

Security software suites should generally detect early versions of Koobface. However, its creators are crafting variants of the malware to try to escape detection, Ferguson said. They do that by obfuscating Koobface's code and compressing it, which can make it more difficult for security software to spot.

Join the PC World newsletter!

Error: Please check your email address.

Tags twitter

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Jeremy Kirk

IDG News Service
Show Comments

Most Popular Reviews

Latest News Articles

Resources

PCW Evaluation Team

Azadeh Williams

HP OfficeJet Pro 8730

A smarter way to print for busy small business owners, combining speedy printing with scanning and copying, making it easier to produce high quality documents and images at a touch of a button.

Andrew Grant

HP OfficeJet Pro 8730

I've had a multifunction printer in the office going on 10 years now. It was a neat bit of kit back in the day -- print, copy, scan, fax -- when printing over WiFi felt a bit like magic. It’s seen better days though and an upgrade’s well overdue. This HP OfficeJet Pro 8730 looks like it ticks all the same boxes: print, copy, scan, and fax. (Really? Does anyone fax anything any more? I guess it's good to know the facility’s there, just in case.) Printing over WiFi is more-or- less standard these days.

Ed Dawson

HP OfficeJet Pro 8730

As a freelance writer who is always on the go, I like my technology to be both efficient and effective so I can do my job well. The HP OfficeJet Pro 8730 Inkjet Printer ticks all the boxes in terms of form factor, performance and user interface.

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Aysha Strobbe

Windows 10 / HP Spectre x360

Ultimately, I think the Windows 10 environment is excellent for me as it caters for so many different uses. The inclusion of the Xbox app is also great for when you need some downtime too!

Mark Escubio

Windows 10 / Lenovo Yoga 910

For me, the Xbox Play Anywhere is a great new feature as it allows you to play your current Xbox games with higher resolutions and better graphics without forking out extra cash for another copy. Although available titles are still scarce, but I’m sure it will grow in time.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?