Facebook DMs Facilitating Koobface to Spread
Trend Micro security researchers caution that a latest version of the notorious Koobface worm is circulating on Facebook through Direct Messages (DMs). The spam entices users towards a harmful site by informing them that someone has posted their video on YouTube.
The company states that as common with these kinds of harmful attacks, the English used in the mail is extremely bad. The URL, is somewhat concealed- the first domain name the user sees is of Facebook. This is because the link does authentically go to Facebook first. Any URL with the pattern http://www.facebook.com/l/{random character};{ redirected URL} shows the Facebook preview page for external links. Reportedly, hackers have been betting that users will avoid the warnings and move on to their site.
Just in case users click on the malevolent link, they are directed to a page showing an image imitating the YouTube player with a pop-up box asking for a Flash player update. Clicking anywhere on the image leads to the installation of a harmful executable website identified as WORM_KOOBFACE.IC by Trend Micro.