Jump to content
M2G

Anonymous Unleashes Facebook Worm, 'Fawkes Virus'

Recommended Posts

Anonymous' buzzworthy threat to take down Facebook on November 5th (Guy Fawkes Day) came and went without a hitch. But did the hacktivist group really just drop its mission to take down the social network?

It appears not. Yesterday, Anonymous released a video saying its programmers have uploaded a "highly sophisticated worm" that takes control of your Facebook account and spreads to your friends' accounts without you being logged in.

According to the video, which you can see below, the so-called "Fawkes Virus" has advanced network self-replication and remote abilities. Once it seizes your account, it spreads itself by making friend requests, sending private messages, and posting malicious links to your friends' walls all without your knowledge. Anonymous also said the Fawkes Virus resembles 2008's Koobface worm which attacked Facebook and MySpace, however the Fawkes virus also receives commands from a remote attacker so it acts like a botnet too.

Based on this description, BitDefender thinks it has identified the worm using Safego, its free anti-scam protection for social networks.

"Backdoor.Bifrose.AAJX" is a backdoor that surfaced on July 8, the same day Anonymous claims it uploaded its virus. The malware gives authors full, unauthorized access to users' accounts, and hides itself by injecting malicious code into the memory process of Internet Explorer, which is how it deletes registry entries in firewalls and antivirus software.

It also acts as a keylogger, meaning it records your keystrokes as a way of stealing passwords, login names, and other sensitive information.

Like most Facebook malware, this one is spread through social engineering. It offers up a link to "New Facebook Video Chat with Voice Features," but if you click the link you begin downloading a poisoned archive called "scan_facebook.zip."

"Once it compromises a system, Backdoor-Bifrose-AAJXdoes pretty much what the hacktivists say, which is: injects itself in IE process, provides a remote attacker unhindered access to the compromised system, records keystrokes and kills several processes of known antimalware solutions, if installed on the computer," wrote George Lucian Petre, product manager of social media security at BitDefender, in a blog post.

But Petre said there are two reasons to think this is not the actual Fawkes Virus. First, the malware doesn't have the self-replication component Anonymous said it would. And second, a well-written Facebook worm backed by a clever social engineering strategy should be spreading pretty rapidly, which is not the case with Backdoor.Bifrose.AAJX. Furthermore most anti-scam protection detects this.

Back in July, Anonymous called on hackers to help it "destroy" Facebook on Guy Fawkes Day, under Operation Facebook. Weeks after the announcement was made, Anonymous clarified it was not actually taking down the social network, prompting many to think it was backing down.

Could the "Fawkes virus" be a reincarnation of Operation Facebook?

"After the worm gets under control, Anonymous will use this to its advantage against corruption, and as an alternative attack towards groups who take on Anonymous. We are Anonymous. We are a legion. We do not forgive. We do not forget. Expect us," the video says.

A commenter of the YouTube video who bills himself as a "legitimate member of Anonymous" said the virus was aimed at Facebook servers, not user accounts.

Sursa: http://securitywatch.pcmag.com/none/290546-anonymous-unleashes-facebook-worm-fawkes-virus#fbid=e0lQtCxg9H8

Link to comment
Share on other sites

Stiu ca au trecut cateva zile , dar am inteles eu bine , chestia asta efecteaza doar pe cei cu IE , daca chiar e asa presupun ca e fail , cine mai foloseste IE ?

Uita-te la statistica dupa site-ul urmator

Aproape 50% din utilizatori de internet folosesc internet explorer. Sau mai bine zis foloseau pentru ca a ajuns cam la 40%

Nu cred ca este scris de ei acest vierme dar cel/cei care au scris acest vierme se folosesc de numele anonymus pentru a se ascunde. Ceea ce ma face sa ma gandesc la cei care au lansat prima oara ideea de a ataca facebook pe 5 nov.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...