A new worm has hit Google’s Orkut and it seems to be hitting it pretty hard, it’s infected via the scrapbook feature and is adding hundreds of thousands of users, similar to the Myspace worm (Samy) that hit in October 2005.
It seems to be fairly unmalicious, more of a ‘look at me – see what I can do’ kind of thing. It’s certainly interested to see that social networking sites are beginning to be the focus of hackers, even if it’s not for money or stealing info..But more of a playground to test their skills.
A fast moving worm is squirming though Google’s Orkut social network, adding hundreds of thousands of users to an Orkut community created by a Brazilian hacker.
The worm, which first appeared on Dec. 19, has been spreading through Orkut’s Scrapbook system at a rapid pace, infecting more than 650,000 users in the space of a few hours.
According to an alert from anti-virus specialist Trend Micro, infection starts when an Orkut user is sent an e-mail telling them that they have a new Scrapbook entry.
Logging into Orkut, the victim is greeted with Portuguese-language text that reads: “2008 vem ai… que ele comece mto bem para vc.” This translates to “2008 is coming…I wish that it begins quite well for you”.
No interaction is necessary. Simply looking at the scrap starts the infection sequence,” says Trend Micro researcher Robert McArdle.
Once the scrap is viewed, it deletes itself and the victim is automatically added to the “Infectados pelo Vírus do Orkut” community.
But yes indeed, it shows the danger of allowing rich user content sanitizing it properly. Haven’t they learned their lessons from what happened at MySpace?
- Santoku Linux – Mobile Forensics, Malware Analysis, and App Security Testing LiveCD
- Appie – Portable Android Security Testing Suite
- Flash Zero Day Being Exploited In The Wild
- The First Reported Facebook Worm/Malware Pops Up – Secret Crush
- Google’s Orkut Hit by Data Stealing Worm – Mw.Orc
- Email Worm Spreading Like Wildfire – W32.Imsolk/VBMania Variant
Most Read in Malware:
- Nasty Trojan Zeus Evades Antivirus Software - 77,404 views
- Hospital Hacker GhostExodus Owns Himself – Arrested - 47,512 views
- US considers banning DRM rootkits – Sony BMG - 44,947 views