Nov9 |
4:56 am (UTC-7) | by
Jonell Baltazar (Senior Threat Researcher) |
We are seeing another development from the Koobface botnet, this time abusing the Google-owned service Google Reader to spam malicious URLs in social networking sites such as Facebook, MySpace, and Twitter.
The Koobface gang used controlled Google Reader accounts to host URLs containing an image that resembles a flash movie. These URLs are spammed through the said social networks. When the user clicks the image or the title of the shared content, it leads to the all-too-familiar fake YouTube page that hosts the Koobface downloader component.
![]() |
![]() |
Google Reader is a free service offered by Google that allows users to monitor websites for new content. It also allows the users to share content from the websites. Any user online can view these pages as they are shared with the public. Sharing any Google Reader page publicly is easy as anyone can click on the share icon in his or her Reader page and the content will appear on his or her public page.
This ability to share content with the public was abused by cybercriminals to use the Google Reader domain to spam malicious links.
We have already contacted Google about this matter to remove the malicious content. As of now we’ve found 1,300 Google Reader accounts used for this attack. The spam URLs hosted through these accounts are now blocked.
Share this article |
|
27 Responses to “Koobface Abuses Google Reader Pages”
Trackbacks
- Koobface Abuses Google Reader Pages | Malware Blog | Trend Micro « "The CTI Blog"
- TrendMicro (TrendMicro)
- DeclanmWaters (Declan Waters)
- UKAGExtensionIT (UK Extension IT NEWS)
- UnderForge of Lack » Blog Archive » 2009.11.10 火曜日
- InfoSec Daily » ISD Episode 4
- kool-gadgets.com » Bot Herders Used Google Apps To Spread Malware
- Menardconnect (Menard Osena)
- Hola PO! » Google Reader infectado de virus
- Google Reader infectado de virus : Blogografia
- Un virus infecta más de mil cuentas de Google Reader Un virus infecta más de mil cuentas de Google Reader « arrayexception.com - Tecnologia y Desarrollo
- Un virus infecta más de mil cuentas de Google Reader | Inicio Mio
- Web-Seiten: Koobface jetzt in Google Reader
- Pages web: Koobface maintenant dans Google Reader
- Best web apps: Koobface now in Google Reader
- Applicazioni Google aggridite dal malware | Sicurezza&Privacy.Trovare.Info
- Blight Watch » Blog Archive » Koobface Attacking Facebook
- Google Reader, ¿’crackeado’? | GrupoHidalgo.com
- Google Reader infectado de virus | Ricón de Ocio
- Social Media Security » Social Media Security Podcast 5 – Google Reader, Privacy, Wave, ChromeOS and Foursquare
- Google Reader infectado de virus
- Koobface manipula las páginas de Google Reader » Countermeasures
- Koobface botnet enters the Xmas season | Zero Day | ZDNet.com
- Attenzione al nuovo virus di Google Reader | GeekTwice
- Attenzione al nuovo virus di Google Reader | Risorse Free
- 2010 – Year of the Zombie Cloud? » CounterMeasures
- 2010 – Year Of The Zombie Cloud? | Business Computing World





