
A month after the emergence of the Conficker, which we learned about at the previous stop on our journey, another destructive virus that spreads through social networks appears on the scene.
We are talking about Koobface, one of the most well-known viruses that hit Facebook, as well as other popular social networks, such as Twitter and MySpace, affecting a total of more than three million computers since the date of its initial appearance.
[alert variation=”alert-info”]The virus first appeared in December 2008 and since then, multiple, advanced, variants have been released. [/alert]
The infamous Koobface worm managed to infect millions of computers, helping its creators earn millions of dollars every year by infiltrating infected systems. According to analysts, between June 2009 and June 2010, the actors behind KoobFace managed to make a profit of more than $2 million.
Methods of infection
Koobface compromises social media accounts and steals users' personal data through a variety of social engineering mechanisms. The most common method of distribution of the virus is through deceptive social media posts that encourage users to follow a link in order to gain access to some kind of entertaining or interesting content.
When potential victims click on the malicious link, they are usually taken to a fake Facebook or YouTube page that requires them to install or upgrade Flash Player, under the guise of viewing an enticing video. Of course, the Flash Player installer or updater is fake, as is the website: the installer is essentially the Koobface virus installer. After the virus is installed, the attackers gain access to the infected computers and send messages with fake links to the victims’ network of friends.
Infected computers are transformed into bots, or zombies, and connect to so-called Command & Control Servers (C&C) to upload stolen data. The computers can also be used by the actors behind the botnet to download or execute any software of their choosing, as well as for other types of illegal activities.
The variants of the virus
Here are some of the most common variants of the virus:
- Worm:Win32/Koobface.gen!F
- Net-Worm.Win32.Koobface.a, a variant targeting MySpace users
- Net-Worm.Win32.Koobface.b, variant targeting Facebook users
- WORM_KOOBFACE.DC, variant targeting Twitter users
- W32/Koobfa-Gen, this variant attacks users of Facebook, MySpace, hi5, Bebo, Friendster, myYearbook, Tagged, Netlog, Badoo and Fubar
- W32.Koobface.D[15]
- OSX/Koobface.A, a Mac variant that spreads via social networks such as Facebook, MySpace, and Twitter
The creators
The five men pictured, Anton Korotchenko, Alexander Koltyshev, Roman Koturbach, Syvatoslav Polinchuk, and Stanislav Avdeiko, appear to be members of the Koobface malware gang, which managed to expose data from millions of computers. The identities of the perpetrators were revealed with the help of German researcher Jan Droemer in collaboration with researchers from the University of Alabama at Birmingham’s Center for Information Assurance and Joint Forensics Research.
And here, somewhere, our journey today into the deadliest viruses of all time has come to an end. We renew our appointment for next Tuesday, where we will get to know, or remember, one of the most dangerous viruses in computer history, which posed a threat not only to the digital, but also to the real world.
Stay tuned to SecNews.




