McAfee Avert Labs has received a new variant of the Koobface worm. Unlike the previous variants, this one spreads using Twitter by sending fake tweets.

These fake tweets contain links to a video; some of these videos are named “My home video.” When users click these links they are prompted to install a video codec. However, upon following the instructions it actually downloads a variant of the Koobface worm and installs it.

At McAfee we detect this variant as W32/Koobface.worm.gen.e and W32/Koobface.worm.gen.h. The detection for this variant will be available to the public in today’s release (DAT 5675).