Social networking - Koobface Worm Lands on Twitter - eWeek Security Watch

Koobface Worm Lands on Twitter

Written By
Brian Prince
Brian Prince
Jul 10, 2009
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Twitter has suspended the accounts of users infected with the notorious Koobface worm that made its name targeting social networking sites such as Facebook and MySpace.

Koobface spreads by posting messages on the victim’s Twitter account with a link that leads to a malicious site that will infect those who visit it with the malware. Researchers at Trend Micro reported that on July 9 a couple hundred Twitter users were infected in the span of a few hours.

Koobface first appeared in 2008, and since then various iterations have touched down on social networking sites from Facebook to Bebo. Just a few months ago, a variant of the worm sought to steal cookies with log-in information for sites such as MySpace.com, MyYearbook.com, Bebo and Hi5 Networks.

According to Trend Micro Advanced Threats Researcher Ryan Flores, Koobface first made its appearance on Twitter a few weeks ago, and used three shortened URLs to lure users to the malicious site. Now, Koobface has upped the ante, and is sending out even more links. The messages being blasted out include Tweets purporting to have home videos and a so-called “Michael Jackson testament.”

The attack utilizes shortened URLs, something security researchers are increasingly warning users about as they grow in popularity. Symantec’s MessageLabs reported earlier this week they had observed a significant spike in spam containing shortened URLs, and phishers have taken advantage of shortening services in the past to trick users on Twitter into visiting malicious sites.

There are some tools and services that can be used to see the full URLs, such as TweetDeck and the Firefox add-on LongURL.

“The danger of these short URLs is that you don’t know where they will take you,” warned Matt Sergeant, senior anti-spam technologist at MessageLabs. “They send an e-mail that’s hard to stop with URL blocking services because they can’t outright blacklist these places like TinyURL. The short URL obscures the real domain name. Spammers have been doing this for a while by trying to find redirection services, and this is the next level of that.”

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.