'Secret Crush' Spreads Spyware Not Love
- By Grey McKenzie
- Published 01/4/2008
Grey McKenzie
National Cyber Security Founder
Cyber security watchdog & one of the nation's leading cyber security experts, Grey McKenzie is also the Founder of SpyCop Security Software.
His clients include members of the Department of Homeland Security, FBI, CIA, State & Local Law Enforcement.
He is regularly consulted by industry leaders regarding cyber security issues.
To schedule a procedural, technical and non-technical network security audit of your company call 902-467-0200
The app, called Secret Crush, sends the victim an invitation to find out who has a secret "crush" on him or her, and attempts to lure them into installing and running the Secret Crush app. But the app instead spreads Zango spyware via an iFrame.
Then the attack gets even craftier: "Before you can find out who might have a crush on you, you need to invite at least 5 friends!" That basically sews up the attack as a social worm, according to Fortinet researchers. Like other Facebook Platform Applications, the terms of service for Secret Crush say users' personal information can be disclosed
Full Story