By BRAD STONE – NYTimes.com
It used to be that computer viruses attacked only your hard drive. Now they attack your dignity.
Malicious programs are rampaging through Web sites like Facebook and Twitter, spreading themselves by taking over peopleās accounts and sending out messages to all of their friends and followers. The result is that people are inadvertently telling their co-workers and loved ones how to raise their I.Q.ās or make money instantly, or urging them to watch an awesome new video in which they star.
āI wonder what people are thinking of me right now?ā said Matt Marquess, an employee at a public relations firm in San Francisco whose Twitter account was recently hijacked, showering his followers with messages that appeared to offer a $500 gift card to Victoriaās Secret.
Mr. Marquess was clueless about the offers until a professional acquaintance asked him about them via e-mail. Confused, he logged in to his account and noticed he had been promoting lingerie for five days.
āNo one had said anything to me,ā he said. āI thought, how long have I been Twittering about underwear?ā
The humiliation sown by these attacks is just collateral damage. In most cases, the perpetrators are hoping to profit from the referral fees they get for directing people to sketchy e-commerce sites.
In other words, even the crooks are on social networks now ā because millions of tightly connected potential victims are just waiting for them there.
Often the victims lose control of their accounts after clicking on a link āsentā by a friend. In other cases, the bad guys apparently scan for accounts with easily guessable passwords. (Mr. Marquess gamely concedes that his password at the time was āabc123.ā)
After discovering their accounts have been seized, victims typically renounce the unauthorized messages publicly, apologizing for inadvertently bombarding their friends. These messages ā one might call them Tweets of shame ā convey a distinct mix of guilt, regret and embarrassment.
āI have been hacked; taking evasive maneuvers. Much apology, my friends,ā wrote Rocky Barbanica, a producer for Rackspace Hosting, an Internet storage firm, in one such note.
Mr. Barbanica sent that out last month after realizing he had sent messages to 250 Twitter followers with a link and the sentence, āAre you in this picture?ā If they clicked, their Twitter accounts were similarly commandeered.
āI took it personally, which I shouldnāt have, but thatās the natural feeling. Itās insulting,ā he said.
Earlier malicious programs could also cause a similar measure of embarrassment if they spread themselves through a personās e-mail address book.
But those messages, traveling from computer to computer, were more likely to be stopped by antivirus or firewall software. On the Web, such measures offer little protection. (Although they are popularly referred to as viruses or worms, the new forms of Web-based malicious programs do not technically fall into those categories, as they are not self-contained programs.)
Getting tangled up in a virus on a social network is also more painfully, and instantaneously, public. āOnce itās delivered to everyone in three seconds, the cat is out of the bag,ā said Chet Wisniewski of Sophos, a Web security firm. āWhen people got viruses on their computers, or fell for scams at home, they were generally the only ones that knew about it and they cleaned it up themselves. It wasnāt broadcast to the whole world.ā
Social networks have become prime targets of such programsā creators for good reason, security experts say. People implicitly trust the messages they receive from friends, and are inclined to overlook the fact that, say, their cousin from Ohio is extremely unlikely to have caught them on a hidden webcam.
Sophos says that 21 percent of Web users report that they have been a target of malicious programs on social networks. Kaspersky Labs, a Russian security firm, says that on some days, one in 500 links on Twitter point to bad sites that can infect an inadequately protected computer with typical viruses that jam hard drives. Kaspersky says many more links are purely spam, frequently leading to dating sites that pay referral fees for traffic.
A worm that spread around Facebook recently featured a photo of a sparsely dressed woman and offered a link to āsee more.ā Adi Av, a computer developer in Ashkelon, Israel, encountered the image on the Facebook page of a friend he considered to be a reliable source of amusing Internet content.
A couple of clicks later, the image was posted on Mr. Avās Facebook profile and sent to the ānews feedā of his 350 friends.
āItās an honest mistake,ā he said. āThe main embarrassment was from the possibility of other people getting into the same trouble from my profile page.ā
Others confess to experiencing a more serious discomfiture.
āYou feel like a total idiot,ā said Jodi Chapman, who last month unwisely clicked on a Twitter message from a fellow vegan, suggesting that she take an online intelligence test.
Ms. Chapman, who sells environmentally friendly gifts with her husband, uses her Twitter account to communicate with thousands of her companyās customers. The hijacking āfilled me with a sense of panic,ā she said. āI was so worried that I had somehow tainted our company name by asking people to check their I.Q. scores.ā
Social networking attacks do not spare the experts. Two weeks ago, Lee Rainie, director of the Pew Internet and American Life Project, a nonprofit research group, accidentally sent messages to dozens of his Twitter followers with a link and the line, āHi, is this you? LOL.ā He said a few people actually clicked.
āIām worried that people will think I communicate this way,ā Mr. Rainie said. ā āLOL,ā as my children would tell you, is not the style that I want to engage the world with.ā
Tags: Antivirus software, Computer virus, facebook, Google, Kaspersky Lab, Malware, malware 2.0, Online Communities, San Francisco, Security, Social network, Social network service, Spyware, Twitter