Koobface is a malware family and botnet best known for abusing social networking platforms to propagate through compromised user accounts. Emerging in 2008, it became one of the earliest widely recognized threats to use social networks such as Facebook as a primary infection and distribution channel. Koobface is commonly characterized as a worm because of its self-spreading behavior through social contacts, and it is also associated with botnet operations.
Koobface targeted Windows systems and spread by sending socially engineered messages through victims’ social-network accounts, luring additional users into executing the malware. Its historical significance lies in adapting classic worm propagation to Web 2.0 platforms, using trust relationships between contacts rather than relying solely on email or network-exploit propagation.
Koobface is widely listed among notable malware and botnet families of the late 2000s. It has been referenced alongside other major crimeware families from that period, reflecting its prominence in mass-malware ecosystems. High-confidence information in the available material supports its role as a socially propagated malware family and notable botnet, but does not provide sufficient corroborated detail here on more specific payload functions beyond that distribution model.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Facebook-spreading worm mentioned only as historical background/comparison to current social-media-focused phishing activity.
Malware 2009 Conficker Koobface Waledac
2009 Conficker Koobface
Koobface is described in the article as a computer worm. The scam caller used its name as the purported infection on the victim's system to justify remote access and payment demands.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.