Headlines
Published On:Thursday, 13 June 2013
Posted by Unknown

Kilim Trojan Hijacks Social Media Accounts with Rogue Browser Extensions



Microsoft experts warn that more and more pieces of malware have started relying on social media. One perfect example is the Trojan dubbed Kilim, or Trojan:AutoIt/Kilim.A.

The Trojan starts infecting computers when users install what they believe to be legitimate software. Once the malware is downloaded and executed, it adds itself to the system registry and downloads two malicious Chrome browser extensions.

These browser extensions allow cybercriminals to hijack Facebook, Twitter, YouTube, Ask.fm, and Vk.com accounts. The attackers can leverage Kilim to like pages on Facebook, send messages and follow certain profiles on Twitter, and even comment on YouTube videos.

The Kilim variant observed by Microsoft posted a message in Turkish on Twitter. The message advertised a website that sold Twitter followers.

“Kilim appears to be selling Twitter followers for a price. There is also a possibility that Kilim can extend its functionality to do more - perhaps stealing sensitive information such as passwords, or even spreading other malware for a price and getting paid per-click-through rates, similar to a pay-per-install model,” Microsoft’s Karthik Selvaraj warned.

Most antivirus solutions should be able to remove Kilim, but some malicious components of the browser extensions might remain. Microsoft has published an advisory on how to remove the components manually.

About the Author

Posted by Unknown on 21:05. Filed under , . You can follow any responses to this entry through the RSS 2.0. Feel free to leave a response

By Unknown on 21:05. Filed under , . Follow any responses to the RSS 2.0. Leave a response

0 comments for "Kilim Trojan Hijacks Social Media Accounts with Rogue Browser Extensions"

Leave a reply

Blogumulus by Roy Tanck and Amanda Fazani

Pages

Powered by Blogger.

Labels

Labels

Blogger news

Labels

Blogger templates

Popular Posts