Most Popular Stories
Events
- Northwestern University Master's in Information Systems
- The AIIM Conference 2012
March 20-22, 2012 — San Francisco, CA - MDSL Telecom Expense Management Roadshow
Feb 21–23, 2012 — New York, Houston, Chicago - CIO Summit
March 18- 21 — Miami, FL
Sponsored Links
Free Newsletter
HOT TOPICS >> The tech world's top flops and fiascos of 2011 | Top 8 features in Windows 8 | Paul's Q&As
INDUSTRY >> Healthcare IT | Government IT | Financial Services IT | Biotech IT | Compliance IT
Free Newsletter
Latest News
Popular Topics
Whitepapers
- Whitepaper: Integrated Analytics and WCM Can Improve Performance & ROI
- The E-discovery Toolbox: What you should look for in a unified e-discovery solution
- Reporting 2.0 – The next evolutionary step in web based business reporting
- Whitepaper: Mobile Device Management Buyer's Guide: An Insider's View of the Market
- Business Intelligence: It's All in the Data
- Data Center: Best Practices
At least one trojan using Facebook as a command channel
Malware authors are always looking for new ways with which to control computers that are infected with a Trojan. This reason is simple--once discovered, security folks are typically quick to shut them down before more damage is done. According to a researcher from Symantec, at least one Trojan has opted to go the route of cloud computing by tapping into Facebook.
Andrea Lelli, a security analyst with Symantec Security Response, wrote that this new malware works by first logging into the mobile version of Facebook. It then moves on to check the notes section of the site for its "orders." Depending on what is found there; up to four different reactions will be triggered, which includes contacting a third party server for additional commands.
Lelli took pains to stress that there are no Facebook exploits or flaws of any kind in Facebook. Indeed, this malware merely logs onto a Facebook account in order to use it as a central node to receive further orders.
Ultimately, Lelli concedes that the Trojan seems to represent a targeted attack. Personally, I reckon this technique of using a specific Facebook account is probably a fast way for its creator to quickly shut everything down by deleting the account.
For more on this story:
- check out this article at Symantec Connect
- check out this article at CNET News
Related Articles:
Facebook expands security to thwart phishing attacks
Facebook withdraws changes in data use
Opening up Facebook status could have utility in the enterprise
Is Facebook a major social engineering threat?
Related Stories
- Researchers uncover BIOS malware Trojan.Mebromi in the wild
- Back door found in software for Energizer Duo USB battery charger
- Facebook struggles to delete old photos from servers
- Hackers tried to extort $50K from Symantec over source code
- Symantec drops warning against use of pcAnywhere, but questions remain
- Tech giants team up to combat phishing with new email specification
- Symantec warns against use of pcAnywhere in wake of code theft
- Symantec source code stolen; company plays down theft
- Microsoft adds XMPP to Windows Messenger
- Symantec: Enterprises failing to manage data encryption keys
Home
| Subscribe | Advertise | RSS |
Privacy
| Site Map
| EditorsTHE FIERCEMARKETS NETWORKFierceEnergy | FierceSmartGrid | FierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceEMR | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceGovernment | FierceHomelandSecurity | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceEnterpriseCommunications | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2011 FierceMarkets. All rights reserved. |
![]() |




