Malicious applications target Orkut

Visitors to infected social network profiles redirected to phishing sites.

Users of the social networking site Orkut have found themselves targeted by malicious applications that redirect visitors to phishing URLs, according to researchers at Kaspersky Lab.

VB100

Orkut, founded by Google at the beginning of 2004, was one of the first big social networking sites. While in many countries its popularity has been dwarfed by that of Facebook and Myspace, it remains hugely popular in Brazil and India. Unsurprisingly, it is also popular with malware writers: among the 16,000+ 'apps' that can be added to a user's profile, some apparently have malicious intentions.

One such malicious application promised the ability to watch TV through one's profile. However, rather than delivering TV content, the application redirected visitors to phishing URLs, which were used to steal login credentials. The malware also used the infected profile to spread itself via messages to the infected users' contacts and within groups.

Another malicious application redirected visitors to a site which demanded a 20 Brazilian real (approx. $12) ransom in order for the users to regain access to their profiles.

Once notified, Google was quick to take the malicious applications offline.

More details are available at Kaspersky's Securelist blog here.

Social networks are increasingly the target for cybercriminals, offering new ways for those with malicious intent to steal sensitive data. At the VB seminar, Sophos's Graham Cluley will discuss cybercrime on social networks, looking at how attacks have evolved, how social networking sites are trying to defend against exploitation, and what companies and individuals can do to better defend themselves.

The VB Seminar takes place at the IET London, UK from 9am to 4pm on 25 November 2010. Secure your place by booking online now. (Or download a PDF copy of the booking form and fax the completed form to +44 (0)1865 543153.)

10 November 2010

Tags: orkut, phishing, ransomware, social networking.   

 del.icio.us  digg this! digg this

0 comments

Leave a comment

Quick Links

Poll
Does your company allow you to use a personal laptop/mobile device to access company resources?
Yes, it's allowed
Yes, it's actively encouraged
No
I don't know
Leave a comment
View 2 comments

Jobs Career Sidebar

VB100 certification
VB100 As expected, the annual VB100 test on Windows XP was an epic. A higher than usual pass rate was tempered by numerous stability issues with the products under test, prompting the unveiling of a new stability rating system. John Hawes has all the details.
See full results.

Virus Bulletin currently has 225,288 registered users.