Using fake or pwned Facebook profiles, attackers have been leading users to a fake YouTube site that claims to require a Flash Player update to play Christmas-themed movie clips.

“In reality, this supposed codec is the download component of the Koobface worm, an approach seen several times over recent months with previous versions of the worm,” writes The Register’s John Leyden. “This time around, the fake video poses as a message from SantA, a tactic cynically designed to appeal to youngsters, instead [of] the usual run of smut or celebrity-themed flicks.”

“Trend Micro has a write-up of the attack here,” Leyden notes.

Click here to read the article at The Register.