The KOOBFACE gang certainly knows how to bring on the Christmas spirit.
KOOBFACE has pushed a new campaign with the help of the new component that we saw deployed last month. The said component executes human-like behavior such as joining Facebook groups and posting messages on Facebook friends’ walls. This new campaign, on the other hand, boosts a timely theme.
The bait is basically the same for this run: posts supposedly published by another user are suggested to be a link to a video. Clicking the link leads to the fake YouTube page typical of KOOBFACE attacks, only this time the page is presented as a Christmas-themed video:
This isn’t the first Christmas-themed attack we’ve seen this year, as we’ve reported spam runs using Christmas in its social engineering ploy as early as September. And judging from what has been observed in the past years, this attack will not be the last.
Thus, as the same for any season, users are advised to be aware and demonstrate caution when online to help stay safe from online threats.