Who – or what – is 'Nicole Santos'?

17 May 2011

By Alexander Villafania

QUEZON CITY, METRO MANILA --  “Nicole Santos” recently became trending topic on Twitter.

But “Nicole Santos” is not a person. She is a malicious Trojan software that made her presence known on May 12 on Facebook. Facebook users receive numerous, profane, and accusatory messages from one “Nicole Santos.”

A shirt was made in her honor by an enterprising person from the buy-and-sell site Etsy. A comedian named Ethan Newberry made a music video parody about her.

The inflammatory messages also contain the statement “Vote for Nicole Santos,” which was used by the Etsy T-shirt maker. Later messages will contain a link that claims to be a solution that will stop the flow of more vulgar messages.

However, the link is actually the script that accesses the users’ Facebook accounts and also taps into the victims’ network to spread itself.

One variation of the “Nicole Santos” Facebook spam had legitimate-looking links, asking users to “VERIFY THE ACCOUNT” that actually lead users to spread the malware even more. As such those within the Facebook network of victims Facebook networks will also get flooded with spam.

Facebook officials have so far stalled the spread after numerous complaints from victims of their service

“Nicole Santos” is a variation of a remove-this-app worm that was previously spread through Facebook. There are several types of this worm such as the Palevo.AP, Netsky.AP

Attacks on Facebook users have been increasing lately as cybercriminals see more effective use of social engineering in the service. People tend to trust people more within their networks, which is what cybercriminals are hoping to target.

There are at least 500 million active Facebook users today, 70 percent of whom are outside the United States. The Philippines as at least 23 million Facebook users and continues to grow.

Software security firm Sophos has some tips that should remind people to protect their social network services from such attacks. These include adjust Facebook privacy settings to protect identity and content, carefully thinking who would be allowed to be part of one’s network, showing "limited friends" to cut-down versions of personal profile.

Other tips include avoiding clicking on suspicious links and reporting them to Facebook’s helpdesk, thinking first what to put in one’s Facebook Wall, and keeping PC security software up-to-date.

***

loQal.ph (http://loqal.ph/ ) is a website owned and operated by Filquest Media Concepts, Inc. It works under the principle of giving voice to the voiceless, empowering Filipinos and uplifting the image of the Philippines by highlighting its unique culture. To do this, the loQal.ph team produces stories, video, photos and other multimedia content types to inspire and celebrate Filipino achievements, ideas, products and places.