Feeds

Bogus LinkedIn profiles punt malware to fools

Beyoncé's not your friend, you berk

Remote control for virtualized desktops

Bogus profiles on social networking website LinkedIn are punting malware to the credulous and starstruck.

Fraudulent accounts in the name of celebrities such as Beyoncé Knowles, Victoria Beckham, Salma Hayek and others are littered with links that take surfers to site harbouring malware, Trend Micro reports. The attack - which is still under investigation - represents a web 2.0 update of the old hacker trick of baiting infectious email attachments with celebrity lures.

As if to reinforce the point, one of the fraudulent profiles is registered in the name of Paris Hilton and tempts the foolhardy with supposed links to her infamous sex tapes.

Another bogus profile created in the name of Beyoncé Knowles claims to offer nude pics of the shapely singer, as recorded in screen shots obtained by Trend Micro here. A quick search of LinkedIn reveals that the offending profile has since been purged. We can expect the others fraudulent registrations to also disappear in short order.

Security researchers have identified that at least some of the maliciously constructed profiles punted malicious scripts, specifically the Decdec-A Javascript code, linked to Trojan attacks.

McAfee adds that hundreds of identikit bogus profiles have been created by miscreants. "The rogue profiles look all alike, with a picture of the celebrity and three links to the parts of the “nude video” like shown in the following picture," McAfee reports.

It's hard to imagine many (if any) would have been taken in by such a crude and transparently bogus ruse. Sophos reckons that the LinkedIn attack might at least partially be geared towards increasing the search engine ranking of hacker-controlled websites.

"Undoubtedly spammers, malware authors and other cybercriminals may be abusing the system to link to their webpages in the hope that it will generate a higher ranking in search engines like Google," a blog posting by Sophos security consultant Graham Cluley explains.

Whatever its main objective, the LinkedIn attack serves to illustrate increased hacker interest in exploiting social networking sites. Over recent days hackers hijacked celebrity profiles registered through micro-blogging service Twitter after exploiting flaws in the password-recover support tool. Separately, ne'er-do-wells launched a phishing campaign designed to trick regular users into handing over account login details. ®

Choosing a cloud hosting partner with confidence

Whitepapers

Choosing cloud Backup services
Demystify how you can address your data protection needs in your small- to medium-sized business and select the best online backup service to meet your needs.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
Driving business with continuous operational intelligence
Introducing an innovative approach offered by ExtraHop for producing continuous operational intelligence.
Why CIOs should rethink endpoint data protection in the age of mobility
Assessing trends in data protection, specifically with respect to mobile devices, BYOD, and remote employees.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.