Social networking - Koobface Botnet Revisited - eWeek Security Watch

Koobface Botnet Revisited

Written By
Brian Prince
Brian Prince
May 28, 2010
1 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

An anagram of Facebook, Koobface has remained one of the successful pieces of malware to target social networks.

First appearing in 2008, Koobface has targeted users of Facebook, MySpace, Hi5, Twitter and other networks. In a new paper, Trend Micro has taken another look at the Koobface botnet (PDF) and some of the changes it has made as it evolved.

Among the major changes to the botnet chronicled by Trend Micro:

“1. Using proxy command-and-control (C&C) servers2. Encrypting the gang members’ C&C communications3. Banning IP addresses from repeatedly accessing KOOBFACE-controlled sites4. Introducing new binary components5. Employing several layers of binary protection with the use of more complex packers“

“These changes pose a greater challenge to security researchers in reverse-engineering existing Koobface binaries and in monitoring the gang members’ C&C communications,” blogged Jonell Baltazar, an advanced threats researcher at Trend. “Though the changes the gang has made to their botnet have made it interesting, someone has to put a stop to their malicious schemes and put the perpetrators where they belong–behind bars.”

Those interested in the minds behind Koobface can read an interesting list of “10 things you didn’t know about the Koobface gang” compiled by ZDNet’s Dancho Danchev.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.