Trend Micro contacted Google informing Google Reader URLs spammed by Koobface :
Trend Micro threat research continues to monitor Koobface criminal activities, including the spamming of URLs by Koobface on social networking sites such as Facebook, MySpace and Twitter. Trend Micro’s flexible solutions, available in multiple form factors, are supported 24/7 by threat intelligence experts around the globe. Many of these solutions are powered by the Trend Micro Smart Protection Network, a next generation cloud-client content security infrastructure designed to protect customers from Web threats. A transnational company, with headquarters in Tokyo
Trend Micro has an advanced integrated threat management technology to protect operational continuity, personal information, and property from malware, spam, data leaks and the newest Web threats. The trend labshas identified a new development in the Koobface Botnet, this time abusing the Google-owned service, Google Reader.
Trend Micro has confirmed that Google Reader URLs were being spammed by Koobface on social network sites. The attack works by having a Google Account controlled by the Koobface gang, host a page with a fake YouTube video. When a victim clicks on the fake YouTube video it redirects to a compromised website – which hosts another fake YouTube video. The compromised website leads to user infection, with the subsequent result of the victim becoming part of the Koobface botnet.
At the time of writing there are around 1,300 known, unique fake Google Reader accounts spammed by Koobface on social network sites. Trend Micro has contacted Google about this incident. This is yet another attack where cyber criminals misuse social networking tools, that were originally designed for fun, for their own profit.
Google Reader is a free service offered by Google that allows users to monitor websites for new content and allows the users to share new content from websites. The feature that enables users to share new content is that which the cybercriminals have abused through the spamming of malicious links.
Comments are closed.