The Register® — Biting the hand that feeds IT

Feeds

Bogus LinkedIn profiles punt malware to fools

Beyoncé's not your friend, you berk

Regcast training : Hyper-V 3.0, VM high availability and disaster recovery

Bogus profiles on social networking website LinkedIn are punting malware to the credulous and starstruck.

Fraudulent accounts in the name of celebrities such as Beyoncé Knowles, Victoria Beckham, Salma Hayek and others are littered with links that take surfers to site harbouring malware, Trend Micro reports. The attack - which is still under investigation - represents a web 2.0 update of the old hacker trick of baiting infectious email attachments with celebrity lures.

As if to reinforce the point, one of the fraudulent profiles is registered in the name of Paris Hilton and tempts the foolhardy with supposed links to her infamous sex tapes.

Another bogus profile created in the name of Beyoncé Knowles claims to offer nude pics of the shapely singer, as recorded in screen shots obtained by Trend Micro here. A quick search of LinkedIn reveals that the offending profile has since been purged. We can expect the others fraudulent registrations to also disappear in short order.

Security researchers have identified that at least some of the maliciously constructed profiles punted malicious scripts, specifically the Decdec-A Javascript code, linked to Trojan attacks.

McAfee adds that hundreds of identikit bogus profiles have been created by miscreants. "The rogue profiles look all alike, with a picture of the celebrity and three links to the parts of the “nude video” like shown in the following picture," McAfee reports.

It's hard to imagine many (if any) would have been taken in by such a crude and transparently bogus ruse. Sophos reckons that the LinkedIn attack might at least partially be geared towards increasing the search engine ranking of hacker-controlled websites.

"Undoubtedly spammers, malware authors and other cybercriminals may be abusing the system to link to their webpages in the hope that it will generate a higher ranking in search engines like Google," a blog posting by Sophos security consultant Graham Cluley explains.

Whatever its main objective, the LinkedIn attack serves to illustrate increased hacker interest in exploiting social networking sites. Over recent days hackers hijacked celebrity profiles registered through micro-blogging service Twitter after exploiting flaws in the password-recover support tool. Separately, ne'er-do-wells launched a phishing campaign designed to trick regular users into handing over account login details. ®

Agentless Backup is Not a Myth

Latest Comments

Not the best place to spread malware...

Surely most people on LinkedIn, which boasts it has the highler echelons of society, would smell a rat when a "celebrity" is using a professional networking site to tout nude pictures?

Apat from which, LinkedIn proactively discourages you from connecting to people you don't already know, so it's quite unlikely you'll be surfing for celebs in the first place.

Not the best place to be spreading malware.

Ian Hendry

CEO, WeCanDo.BIZ

http://www.wecando.biz

0
0

Hard to imagine?

"It's hard to imagine many (if any) would have been taken in by such a crude and transparently bogus ruse..."

...but then again, I got a nigerian spam yesterday - totally normal, except FROM: was "NIGERIAN SCAMMERS". Seriously.

0
0

Berk etc.

Akshully, Berkshire Hunt is rhyming slang for C***. Berk is the approved short form version.

Something smells of fish, though......

0
0

More from The Register

 breaking news
NSA PRISM snoop-gate: Won't someone think of the children, wails Apple
10,000 things probed, mostly about missing kids, Alzheimer patients, we're told
 breaking news
NSA PRISM-gate: Relax, GCHQ spooks 'keep us safe', says Cameron
Whatever they are up to, it's all above board, we're told
PRISM snitch claims NSA hacked Chinese targets since 2009
Snowden suddenly looks safer in Hong Kong after revelations
 breaking news
US chief spook: Look, we only want to spy on 6.66 BEELLLION of you
Americans assured they are not in the NSA's sights
Speech-to-text drives motorists to distraction
Will talking to you mean I crash into that car up ahead, Siri?
DHS warns of vulns in hospital medical equipment
Has your doctor's anasthesia machine been hacked?
 breaking news
'BadNews is malware' says outfit that found it
Google says code harmless but Lookout says code base is evolving
Panda-peddlers cuffed for chess gambling gambit
More porridge on the menu for Chinese coders after second offence
 breaking news
Yes, maybe we should keep hackers in the clink for YEARS, mulls EU
Watch out black hats, they just might throw away the key
Microsoft borks botnet takedown in Citadel snafu
Stupid Redmond kicked over our honeypots, wail white hats