07 Jan 2009
A rash of fake profiles on business networking site LinkedIn could put users in danger of malware infection.
Researchers at McAfee said that several hundred phoney profile pages on the service are tempting users with the promise of nude photos of celebrities.
When the user clicks on one of the links, they are taken to an external site which attempts to launch an iFrame browser exploit and then redirects the user to other potentially harmful sites.
"When an unsuspecting user follows the lure, he will end up on different malicious web sites trying the classic social engineering tricks of the 'missing video codec' or a fake anti-virus scan telling the user his computer is infected with malware and offering 'free' scanning software, which in fact is the real threat," wrote McAfee researcher Micha Pekrul in a blog post.
"So beware when following links, even on trusted Web 2.0 platforms like LinkedIn."
LinkedIn is used almost exclusively by professionals to manage business contacts and keep in touch with former colleagues, and has largely been spared from the scam attempts that plague larger sites.
Like all social networking sites, however, researchers expect LinkedIn to become an increasingly popular way for cyber criminals to lure new victims over the coming year.
The high traffic rates on such sites, combined with the ability to upload and share content, make the services an ideal medium for phishing and malware distribution.
A textbook example surfaced earlier this week when Twitter was hit by two major attacks. A large phishing operation plagued many of the site's users, while several high profile celebrity accounts were hacked and defaced.
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
My Client seeks an experienced Programme Director / Manager...
Senior Business Analyst (Systems Team Lead) We are...
Description: Drupal Developer (Back End) -Technical Consultancy...
A Global Business seeks an experienced Business Analyst...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
Tighten up the security
We certainly seem to be hearing more and more about trouble in the social media networks including LinkedIn, Twitter and Facebook. We should pay extra special attention to your account security on the social networks.
Posted by: Jason 12 Oct 2009
LinkedIn not a great place for malware
Surely most people on LinkedIn, which boasts it has the highler echelons of society, would smell a rat when a "celebrity" is using a professional networking site to tout nude pictures? Apart from which, LinkedIn proactively discourages you from connecting to people you don't already know, so it's quite unlikely you'll be surfing for celebs in the first place. Not the best place to be spreading malware. Ian Hendry CEO, WeCanDo.BIZ http://www.wecando.biz
Posted by: Ian Hendry 07 Jan 2009