Facebook malware scam takes hold
- 04 February, 2012 08:25
- Comments
A "worrying number" of Facebook users are sharing a link to a malware-laden fake CNN news page reporting the U.S. has attacked Iran and Saudi Arabia, security firm Sophos said Friday.
If users who follow the link then click to play what purports to be video coverage of the attack, they are prompted to update their Adobe Flash player with a pop-up window that looks very much like the real thing. Those who accept the prompt unwittingly install malware on their computers.
Within three hours of the scam's first appearance, more than 60,000 users had followed a link to the spoofed CNN page, according to Sophos Senior Security Advisor Chester Wisniewski. Facebook removed that link, but others are still being shared.
"The bad guys are rotating through scam pages trying to stay ahead of Facebook," Wisniewski said.
Facebook did not immediately respond to a request for information on how widespread the problem was or whether its own security had been breached, but Wisniewski said that there are a number of ways that status updates could appear without users' knowledge. Their Facebook accounts could have been hacked, allowing a third party to update their status. It is also possible for scammers to exploit weaknesses in the social networking platform itself or in Web browsers to post a status update using Java Script.
A representative status update shown in a screenshot on the Sophos blog reads, "U.S. Attacks Iran and Saudia Arabia. F**k :-( [LINK] The Begin of World War 3?"
Users who accepted the Flash player update prompt installed a fake antivirus tool on their computers. That tool would then alert them that their computer is infected with malware that can be eliminated for a fee. Such scams are one of the most lucrative, Wisniewski said, noting the irony that they net far more money than the legitimate security products Sophos and other security companies peddle.
In addition to a healthy dose of skepticism that the U.S. would attack its ally Saudi Arabia, Facebook users can avoid the scam and others like it by updating Flash only from Adobe's own website rather than from pop ups.
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
-
Australia's first 4G smartphone is the HTC Velocity 4G
-
Swedish e-commerce startup's execs linked to NYC sex crime
-
Face Time - Interview with John Brennan and Robert DiStefano
-
How to implement next-generation storage infrastructure for Big Data
-
Pfizer's Future Depends on IT Transformation
-
Top 5 Threat Protection Best Practices
Small businesses are especially vulnerable to computer viruses and lost or stolen data, since they typically lack the IT resources to deal with these threats. Inadequately protected computers open the door to annoying infections, or worse, serious business disruption. Below are five simple and effective strategies to help you protect your business against an ever-increasing number of threats. -
Traditional Backup is Dead - Are you prepared?
Conventional backup and recovery approaches clearly can't keep up with ever-growing storage rates. It's time to take on a new strategy. -
HP Security Action Plan for Enterprise Printing and Imaging
Security is a part of how we work. When you walk through the front door of your office every morning, you probably pass a level of security. At your desk, it’s likely you log in to your computer and access files over a secure server. From security badges and ID cards to network firewalls and software security, it may seem like your organisation has taken every measure to protect its property, people and data. This action plan outlines a step-by-step approach to help you develop a plan that improves the security of your printing and imaging environment and boosts your business.
-
Macs for Seniors for Dummies®
-
WileyPlus High School Stand-alone to Accompany Microsoft Office Excel 2007, Exam 77-602, Withstudent Cd-rom, High School Edition
-
Microsoft SQL Server Reporting Services Recipes
-
Computing for the Older and Wiser - Get Up and Running on Your Home PC
-
Flsh Pral Digital Classroom
-
IMac for Dummies, 6th Edition
-
Wireless and Mobile Network Architectures
-
Introduction to Multiagent Systems 2E
-
Color Correction for Digital Photographers Only








Comments
Post new comment