::Trend Micro Threat Resource Center::

Showing posts with label social networking. Show all posts
Showing posts with label social networking. Show all posts

11 February 2015

Twitter’s Own CFO Just Had His Twitter Account Hijacked

Twitter has a bit of a security problem. Taylor Swift, Chipotle, Newsweek — it seems each day brings another hijacked account or two.

Click to enlarge

For about 20 minutes this morning, Noto’s account was blasting out a massive torrent of spam.

It looks like the account was hijacked somewhere around 11:10 a.m. PT and recovered by 11:30. In that stretch, nearly 300 spam tweets were sent to some of Noto’s 13,000 followers.

Twitter has yet to comment on how the account might have been taken over. Given that it was used for spam rather than a political message, it’s possible that this wasn’t a targeted attack, instead relying on something like an old, forgotten API key left behind on a leaky third-party service.

It’s perhaps a bit revealing, though; if the company can’t keep the account of one of its own top executives locked down, what about its other 288 million active users?

28 November 2014

Twitter to start snooping at which apps you have installed - here's how to opt out


Twitter is set to start peeking on users' iPhones, iPads and Androids in order to see which apps they
have downloaded.

The company will start collecting the list of apps installed on those smartphones and tablets so that it can, in its own words, "deliver tailored content that you might be interested in."

A support article says the additional data collection will allow Twitter to make better recommendations on who to follow, as well as insert content it thinks you will find interesting into your feed.

The new feature, which Twitter has named "app graph," could tie in with the company's recently announced Instant Timeline feature which takes new users' areas of interest and the people their contacts follow, and serves up a feed created for them in order to better personalise Twitter from day one.

By collecting data about other installed apps, the feature would be better positioned to create a more relevant starting timeline.

Of course, the main benefit to Twitter will be the ability to use the collected information to surface more targeted adverts. Or, as Twitter puts it, show you more promoted content it "think[s] you'll find especially interesting."

Twitter says it will only record the list of apps you have installed, not how they are used.

So, for example, Twitter will be able to see that you have Spotify on your phone, but not that you're listening to the same 80s classic over and over and over again.

While entry into the new tracking system is automatic and opt-in by default, Twitter has promised to alert users when the new feature is turned on.

We will notify you about this feature being turned on for your account by 
showing a prompt letting you know that to help tailor your experience, 
Twitter uses the apps on your device. 
Until you see this prompt, this setting is turned off and 
we are not collecting a list of your apps.

If you don't want your apps to be snapped up by Twitter's data gobblers, here's how to turn it off:

Twitter for Android
  1. Tap the overflow icon (looks like 3 vertical dots)
  2. Choose Settings.
  3. Select your account
  4. Under Other, turn off Tailor Twitter based on my apps.

Twitter for iOS
  1. Tap the Me tab, and then the gear icon
  2. Choose Settings
  3. Select your account
  4. Under Privacy, turn off Tailor Twitter based on my apps.
  5. Once you opt out, Twitter says it will remove your app graph data from Twitter and stop future collection.
If you don't yet see the option then Twitter won't have started tracking you yet.

If you want to stop the collection before it's started, Twitter says you can turn on Limit Ad Tracking on your iOS device by going to Settings and Privacy.

If you're an Android user, go to Settings, tap the Google account, choose Ads and then turn on Opt out of interest-based ads.

27 September 2014

Facebook Messenger has abundance of permissions

Lately, there has been quite a bit of talk about how Facebook Messenger for Android has an abundance of permissions, permissions that may seem out of the spectrum of what a messenger app should need.

Since Facebook no longer allows users to use its flagship Facebook app to send messages, users must now install the new Facebook Messenger app to regain this functionality.

This isn’t the first time questions have risen about Facebook’s long list of permissions. When they first introduced the Facebook app, it came packed with permissions (and it still does).

Let’s first look at the Facebook Messenger app permissions:


In comparison, the Facebook app has all the same permissions, plus Device & app history permissions.

Before you decide to toss Facebook aside and start using Google Hangouts, the messenger for Google Plus, note that it has the same permissions as Facebook Messenger.

The question is whether or not Facebook, Google, or other well-known companies with apps in the Android Play store need the long list of permissions in there apps?

Let’s look at some of the more troubling permissions in Facebook Messenger; location, SMS, Camera/Microphone, and Device ID & call information.


  • Location permissions are used to show the location of where you are sending the message from.  It’s arguable whether this is really necessary, but the function is there.
  • SMS is being used for when you add a phone number to a Facebook messenger account, it can confirm the phone number being used by sending a confirmation code via text message.
  • Camera permissions are so you can use the camera to take a picture to send through messenger, and microphone permissions are used so you can record and send audio.
  • Device ID & call information is used to initiate outgoing calls so you can call friends and family through the messenger app.
  • In other words, Facebook is NOT tracking your every move, NOT looking at your SMS messages, NOT using your camera and microphone to spy on you, and NOT tracking all your call information.

Facebook and other companies are going to continue to come out with feature rich apps, and the more features they have, the more permissions they will need.

Many of these permissions would be a huge red flag that something fishy might be going on. The difference between good apps and bad apps is how the permissions are used in the code.

It’s the code that contains the malicious intent, but it’s not always easy to tell what permissions are legitimately being used, and which are being exploited.

That’s why we are here to make those hard decisions to keep our customers safe.  So yes, it’s a little scary when apps have an overwhelming list of permissions. This is especially true with social media apps that handle content that some may consider “private”.

One more thing worth mentioning: with all these permissions, you want to make sure you have the correct Facebook Messenger app from the Google Play store.

You’ll know it’s the right one when you see the package name “com.facebook.orca” with a large amount of downloads and reviews.  The package name displayed in the URL on the Google Play site after “id=”.  It would be bad news to get a knock off app with this many permissions from a third-party market.  Stay safe out there.

22 September 2014

Facebook To Begin Charging Users $2.99 / Month'- Totally BULLSHIT!

Facebook going to charge users per month?? Nobody expected such a news story this week, but it seems that Facebook will No longer be a Free Service, according to reports claimed by the National Report, "Facebook To Begin Charging Users $2.99/mo Starting November 1st", which turns out fake. Thank God !!


This new report is circulating via social media which claims that the social networking giant will begin charging charging $2.99 (€2.33) per month for each user starting November 1, 2014 in an effort to fight against the rising costs the company is facing.

Of course, the claims are simply untrue. Facebook has not announced any such plans to begin charging its users a monthly fee for access to the regular site services that has more than 1.3 billion monthly users.

NICELY FRAMED HOAX
The report comes via the 'satirical' fake-news website, which is a complete Hoax, just like many similar 'Facebook to start charging' hoaxes before it. But What make it different from those other hoaxes?? It’s the way it framed so nicely that it acquired everybody's attention on the the Internet.

“At a press conference this morning, Facebook rolled out their monthly service plan which begins November 1st of this year. The social media giant says they will start charging members $2.99/mo to use the services that the site has to offer,” reads the fake news report.

Not just this, the fake-news article also quoted some fake statements from Facebook CEO Mark Zuckerberg, which made it even more convincing.

“After thinking long and hard about this decision, at the end of the day, we were forced to add this monthly fee,” said Facebook founder and CEO Mark Zuckerberg. “If we don't do something about our rising costs now, Facebook could cease to exist in the near future.”

FACEBOOK IS FREE AND ALWAYS WILL BE
National Report considers itself as Satirical, as in its disclaimer, the site mentioned that it is a news and political satire web publication, which may or may not use real names, sometimes in semi-real or wholly fictitious ways. Although many are confused about this because there are so many fake news that are making their way out of the site and are believed to be true.

The site also reads that every news article on their website is fiction and fake news, which do not relate with the truth in any way. But, the fact that the site presents their news in a manner similar to that of other legitimate news websites makes things much more difficult to distinguish.

For those who believe this story to be true are informed, regardless of all claims that Facebook is about to start charging, that these claims are totally nonsense. Facebook isn’t charging its users for their services, and according to their own homepage, it says, 'It's free and always will be'.

Always take a while to verify these kind of sensational claims regarding Facebook or any other online services. also, don't spread any misinformation and junk with your Facebook friends, before confirming the whole thing.

08 September 2014

Review your Facebook privacy settings with Privacy Checkup

Facebook's Privacy Checkup tool - informally dubbed "Privacy Dinosaur" - has been made available for use to all users of the popular social network.

Initially introduced and tested in April by a small number of user, the tool has obviously passed muster, and the rest of the users will soon be prompted to try it out via a pop-up.

Or, they could test it right away, by clicking on the padlock icon in the top right corner of their Facebook page and choosing the (unmissable) option.



In three steps, the tool will invite you to review and change the default setting determining who will see your posts, the settings for the apps you've logged into with Facebook, and personal information you have included in your profile.

The tool is extremely easy to use and doesn't overwhelm users with information, and will hopefully give them a push towards reviewing all their privacy setting and learning more about them.


One might wonder why, after years of pushing users to share more info publicly, Facebook has now started worrying about user privacy?

It's likely that Facebook is trying to rehabilitate its image with the greater public, and make users who worry about privacy continue to share useful data.

Earlier this year, at the F8 developers conference, the company announced that users who are worried about data collected via apps will soon be offered the choice to login to third-party apps anonymously.

Facebook is apparently after user numbers and data, but for themselves. The company is reportedly working on a mobile ad network similar to Google's, as it's looking to get a bigger cut of the ad revenue.

23 August 2014

Hackers breach social network MeetMe

Anyone who logged into social network MeetMe between Aug. 5 and Aug. 7 is being asked to change their password because hackers breached the MeetMe network and compromised certain user information.


How many victims? Undisclosed.  

What type of personal information? Usernames, email addresses and encrypted passwords.

What happened? Hackers breached the MeetMe network and gained access to the information.

What was the response? The vulnerability has been closed. MeetMe is notifying users and recommending that they change their passwords.

Details: Hackers gained access to the information between Aug. 5 and Aug. 7. Financial information was not compromised.

Quote: “There is no evidence that any accounts were accessed, but MeetMe contacted its users regarding the incident by email and with a notice posted on the site,” Aaron Curtiss, senior executive with communications firm G.F.BUNTING+CO, told SCMagazine.com in a Tuesday email.

Source: A Tuesday email correspondence with communications firm G.F. BUNTING+CO.


03 April 2013

Think twice before you rush to post your PII for that freebie on Facebook!

Looks like any other product Facebook page? Think again.
Click to enlarge

Another case of misuse of social media, by consumers - that is case study worthy.
I was alerted of people posting their personal particulars (or commonly known as PII in US) on Loreal Singapore's facebook wall in exchange for potential freebies. Read POTENTIAL.

Don't believe how crazy can that be? Here's proof:

Click to enlarge

There's just so much private data there waiting to be mined. The PII have been sanitized to protect their privacy, but I'm thinking my attempts will prove to be futile as the Facebook page is accessible by the general public even without logging in. 

24 March 2013

Ten simple things you should do this Data Privacy Day



When was the last time you ran a search on your own name – do you know if someone has been pretending to be you, or if unwanted eyes have easy access to your personal details?

Don’t stand idly by as the trail you leave online gets larger – be vigilant and take steps to protect your own information. In line with Data Privacy Day on January 28, here are ten simple things you can do to better protect
the information you share online.

1. Password protect your mobile devices – only 6 in 10 Singaporeans use passwords on their mobile device. Leaving your devices unprotected is equivalent to leaving your home or car unlocked. If you’re lucky, no one will take advantage of the access. If not, you might find yourself at the mercy of cyber risks and fraud.

2. Run a search on yourself – it’s not narcissistic, and is an easy way to stay on top of what’s available about you online. You never know who might be assuming your identity or sharing your private information.

3. Be stingy with your personal details
– some websites will prompt you for information such as your email, address or phone number. Be cautious as this information might end up being used in unexpected ways.

4. Mobile security software can add another layer of protection
– yes it exists, and yes it works.

5. Unknown sources are usually bad news
– emails and text messages that contain links or ask for information might do you more harm than good. Make sure you know who the sender is before opening these messages.

6. Be in charge of your privacy settings
– some social networks and applications can share your personal information and location with strangers. You should only share personal details with those you trust.

7. Download apps from reliable sources
– mobile malware is spreading via fake app markets. Be mindful of what apps you’re downloading and where you’re downloading them from.

8. Keep your apps updated
– security patches exist for a reason, use them when available.

9. Log off and log out
– unless you want others to have easy access to your accounts, you should always log out after use.

10. Stay informed
– keep up to date with the latest mobile threats and dangers by visiting websites such as MobileSecurity.com, which has the latest news on all things related to protecting yourself and your mobile devices.

14 March 2013

Fake Pope Twitter account proves malicious potential of breaking news

Mere minutes after it become publicly known that Argentinian cardinal Jorge Mario Bergoglio was elected to serve as the new Pope, Internet users around the world began searching for him on social networks.



A Twitter account (@JMBergoglio) using his name and photo was promptly discovered, and as many users considered it to be legitimate, it attracted over 100,000 followers in just a day. They were able to read that he was very happy at being elected as Pope, and that kids are going to love him more than Santa Claus.

But, as it turns out, the account is fake and has been promptly suspended by Twitter, presumably after the Vatican PR machine got involved and requested it.

Luckily for the followers, the individual behind the account wasn't set on promoting malicious links, but this example shows just how easy it is for scammers to find a way of reaching hundreds of thousands of users by simply taking advantage of the massive interest some global events garner.

Even the Verified Account option is sometimes not enough to guarantee that the account you follow belongs to the person you are interested in.

All in all, users are advised to never follow links included in tweets, Facebook posts, or emails unless they are absolutely, 100 percent sure they will not take them to malicious sites.

29 September 2012

Malware Infested Twitter Messages Contain Fake Facebook Links

Twitter users need to be on the lookout for a new round of malware-carrying spam messages that are coming from compromised accounts, possibly even from Twitter profiles they trust.

If you receive a direct message suggesting that someone has posted or tagged you in a Facebook video, beware. Clicking on the link could infect your computer with malware. According to the Sophos Naked Security blog, the direct messages are not originating from spam accounts, but instead compromised accounts of friends - which makes it even more likely that a careless user could fall victim.

Although the messages vary, the common thread between all of them is that they contain a "facebook.com/________" link and mention that a video of you has been posted on Facebook. "Your in this facebook.com/________ video, LOL" reads one spam message, while another says "you even see him taping u, that's awful."

When an unsuspecting user clicks on the link, they are shown a YouTube video player and prompted with a message that says, "and update for YouTube player is needed. It says that it will install Flash Player 10.1 onto your computer, but instead installs "Troj/Mdrop-EML, a backdoor Trojan that can also copy itself to accessible drives and network shares," according to Sophos.

Of course, clicking on any link in a direct message that links you offsite is risky, and the fact that these messages are coming from trusted sources makes it especially tricky. However, the fact that the messages contain various misspellings and gramatical errors should suggest to the discerning user that they might not be legit.

11 May 2012

55,000 Twitter Accounts Hacked, Passwords Exposed


Hackers appear to have successfully exposed the passwords of as many as 55,000 Twitter accounts yesterday, sparking the website to conduct an investigation into just how the security breach occurred.


The hack was first reported on the blog Airdemon.net where it was said that "anonymous hackers" - note that it's not the proper Anonymous, as in the hackivist collective, but it's not clear whether that punctuation difference was intentional or not - gained access to the the accounts, some of which are said to belong to celebrities. The account information was so enormous that it took five pages on Pastebin to share all of the information.

According to CNET, Twitter is looking into the breach and have notified the affected accounts with notices to reset their password.

Yesterday evening, Twitter, via the @twittercomms account, said that many of the accounts affected were duplicates or spam-ish.
The list of alleged accounts & passwords consists of more than 20,000 duplicates. Also suspended spam accounts & incorrect login credentials
12 hours ago via Twitter for Mac ·  Reply ·  Retweet ·  Favorite · powered by @socialditto

After crunching the numbers and identifying the duplicate accounts shared on Pastebin, Anders Nilsson at Säkerhetsbloggen determined that the total amount of actual accounts is 34,062 and, of those, only 25,068 appear to be legit. He also postulates that a majority of the accounts appear to be associated with email accounts from Brazil, which would make sense since when I looked at the list of account info on Pastebin my browser offered to translate the webpage into Portuguese. More interesting, Nilsson also points out that the list of yesterday's hacked accounts appear to be accounts that were hacked last summer.

So maybe Twitter's right to downplay this security breach and it's not really as threatening or legitimate as it first appeared to be. Do you think Twitter's responded appropriately, or should it be taking the matter a little more seriously? Think this situation is more hoax than actual hack?

Update [14 May 2012]: Even though the sentiment is pretty much summarized above, here is the official Twitter statement a spokesperson provided to WPN:

We are currently looking into the situation. In the meantime, we have pushed out password resets to accounts that may have been affected. For those who are concerned that their account may have been compromised, we suggest resetting your passwords and more in our Help Center.

It's worth noting that, so far, we've discovered that the list of alleged accounts and passwords found on Pastebin consists of more than 20,000 duplicates, many spam accounts that have already been suspended and many login credentials that do not appear to be linked (that is, the password and username are not actually associated with each other).

08 April 2012

Polymorphic Facebook scam targets users

An insidious scam that can result in multiple malware downloads is currently targeting Facebook users, warns Bitdefender.

It starts rather predictably, as users inadvertently share links to a supposedly leaked pornographic video. If their friends follow the link, they are faced with a request to download a Divx plugin in order to watch the video:


"The page recommending users to install the missing plugin features several other elements to encourage users to keep clicking," points out Bitdefender.

"The video’s name hints that the sex tape belongs to a celebrity; the warning that the user’s antivirus must be disabled works on reverse psychology: though prospective viewers know this action is risky, they do it precisely because they have been warned about it; and the reference to age verification further hints at the salaciousness of the video."

When run, the downloaded "Extension YouTube" immediately changes all newly opened tabs to a page advertising an adult chat service, then leads the user to to another page that supposedly hosts the video the users wanted to check out in the first place.

But, now the users are asked to download another piece of software - the "7pic Video Premium Player".

Unfortunately for them, it's another bogus extension that allows the scammers to access hijack the users' account by accessing the needed cookie information and propagate the scam further.

“This is an interesting and quite complex type of scam," says Andrei Serbanoiu, Bitdefender Online Threats Analyst Programmer.

"In data security lingo, this would qualify as a polymorphic attack, which basically means that the malicious content served can be changed by the attacker thanks to the browser extension installed. If one user lands on the adult chat page, another may reach the malware downloader or even a whole different web page set up for phishing.

07 April 2012

Instagram users targeted with spam

It's almost a given that any social service, network or app that attracts a large number of users will eventually be facing the spam and scam problem.

It happened to Facebook, Twitter, YouTube, Pinterest and many others, and Instagram - the popular photo sharing application and the network of users that grew up around it - is no exception.

Symantec researcher Satnam Narang shared the example of a spam campaign that he encountered when a user commented on a photo of his, saying that the Best Buy was giving away $100 gift cards for free to Instagram users.

The offered shortened link takes the users to a page where they are asked to input their cell phone number in order to win the card, and only if they scroll all the way down will they be able to notice the fine print saying that prior to qualifying for their prize they will be presented with optional third party offers, and that they need not to complete the offers in order to qualify.

The third party "offers" look like this, and is not really clear what exactly they are offering:


Notice that the offers can be skipped without inputing the information, but the links to do so are difficult to notice as they are small text links put in the upper right corner and designed to blend in with the background.

The collected information is likely to be used for future spamming, but it's likely that users have also unknowingly agreed to subscribe to a pricy service.

"If you have given your cell phone number up during one of these scams, be sure to check your next phone bill to see if there are any unwanted charges on it for some kind of subscription service," says Narang.

He also advises users to report these type of offers by clicking on the wheel icon in the top-right corner of their Instagram profile and reporting the user that posted them.

As we haven't seen an overwhelming amount of spam hitting Instagram users, I guess that some of the changes the service has introduced do work.

30 March 2012

Scammers advertise Pinterest bots on Facebook

Internet scammers have launched a paid advertising campaign on Facebook targeting Pinterest fans, bringing the hunt for victims to a higher level of investment and sophistication to online social fraud, according to Bitdefender.

The ad, created by a web site promoting Pinterest bots, promises to show interested parties how to “make money with Pinterest”. This is an element of novelty as scammers actually seem to be taking money out of their pockets to make sure that their scams hit it big.

The paid advertising campaign can increase the efficiency of scams as the Facebook ad targeting mechanism allows you to “define your ideal audience by what they are interested in, using terms people have shared in their Facebook profiles (timelines). These may be drawn from their listed interests, activities, education and job titles, pages they like or groups to which they belong,” according to Facebook’s help centre.

The embedded link in the ad takes users to a web page that features a survey they are supposed to take in exchange for a Visa gift card and an e-mail address submission form for possible subscribers. While the “free gift card” method is reminiscent of a recent spam wave that hit the Pinterest platform, the bot-based money making mechanism advertised in the ad is very similar to the #followback scams on Twitter.

“Pinterest is one of the hottest social platforms of the moment, which would explain scammers’ malicious interest in its huge user base. The interesting thing about this scam is that it pays a twisted tribute to Facebook by targeting its users with ads,” said Catalin Cosoi, Chief Security Researcher at Bitdefender. “We should all be on the lookout for new, customized scam mechanisms.”

The Pinterest team indicated that the spam and money-making mechanisms violate the platform’s acceptable use policy in two areas: unsolicited advertising materials and use of the service for third parties’ benefit without Pinterest’s agreement. Pinterest recently updated its policies to eliminate a few unclear matters regarding ownership of pinned content and more general copyright issues.

“As a growing service, Pinterest is not immune to challenges faced by sites across the web including spam and phishing. However, it is a tremendous priority for us to quickly address them. Our engineers are actively working to manage issues as they arise and are revisiting the nature of public feeds on the site to make it harder for fake or harmful content to get into them”, stated Erica Billups from The OutCast Agency, on behalf of Pinterest.

21 March 2012

Apple, Facebook and others named in privacy lawsuit

Thirteen individuals have filed a lawsuit against a number of app makers including Path, Facebook, Instagram, Yelp and Rovio, accusing them of uploading the information stored in their mobile phones' address book to their servers and using the appropriated data for their own ends, Venture Beat reports.

The suit, filed in U.S. District Court in Austin, Texas, is the result of last month's discovery by app developer Arun Thampi that the Path app copies the entire contents of the users' address books and sends them to the company servers without asking the users for permission or notifying them of it in any way. Path has subsequently admitted to doing it.

Further investigation into the matter revealed that other app developers have seemingly been doing the same thing, and Twitter has also confirmed the practice, explaining that the data is collected and stored only if the user takes advantage of the “Find Friends” feature because it scans the address book to search for individuals who also have a Twitter account.

Even though the developers of the apps have been found violating Apple's privacy policies by distributing these apps through its App Store, the company has also been named as a defendant in the suit because it approved the apps, allowing them to be sold from its Store.

"Literally billions of contacts from the address books of tens of millions of unsuspecting wireless mobile device owners have now been accessed and stolen," claim the plaintiffs. "The surreptitious data uploads—occurring over both cellular networks and open, public wireless access nodes in homes, coffee shops, restaurants, bars, stores and businesses all across the nation—have, quite literally, turned the address book owners’ wireless mobile devices into mobile radio beacons broadcasting and publicly exposing the unsuspecting device owner’s address book data to the world."

As a result of the companies' wrongful actions and/or inaction, the plaintiff say that they suffered damages and incurred many expenses, for which they want to be reimbursed. They accused the companies of having invaded their privacy, having been negligent, breaching their devices, earning money by using and selling things that don't belong to them, and more.

The plaintiffs asked for the suit to be allowed to gain class-action status, and their attorneys say that the list of defendants could also be expanded.

25 July 2011

"Amy Winehouse death video" scams hit Facebook users

The past weekend has been rife with bad news that captured the attention of the greater public, and online scammers have wasted no time in taking advantage of it.

Facebook users have predictably been targeted with various scams. First came the ones exploiting the Oslo bombing news, and then followed those luring victims in with non-existent videos of the last moments of the famous and recently deceased singer Amy Winehouse.

According to Sophos, variations of "Leaked Video!! Amy Winehouse On Crack hours before death", "Video leaked of Amy Winehouse's death!!! Warning: Graphical Content" and "SHOCKING - Amy Winehouse's Final Minutes" messages offering a link to the purported video unsurprisingly take users to pages where they are asked to like the page and to take a survey before being allowed to see it:


If you are one of the people who fell for this type of scam, be sure to remove any trace of it from your account ("Likes and interests" section, for example) and news feed, and to report the scam to Facebook.

Also remember that when it comes to unexpected and often shocking global news, legitimate news sites are always a better source of information than your Facebook friends.

Even when it seems that the offered link is the URL of a legitimate site, it might be better to go to that site by typing in the domain name in and then using the internal search feature in order to find the wanted news item.

24 July 2011

Oslo bombing Facebook scams infecting 1 user per second

Websense has found an alarming number of Facebook scams taking advantage of yesterday's tragedy in Oslo, Norway.

Right now it seems to be infecting one user every second. The scam is a form of ‘clickjacking’ that replicates itself on users’ walls after they click on fake posts within their news feed.

Example of viral Facebook exploit:


Users should be cautious when clicking on breaking news trends and stories within search results related to the Oslo tragedy.

Searching for breaking trends and current news represented a higher risk (22.4%) than searching for objectionable content (21.8%), including pornography.

“This Facebook scam is unfortunate, but a very real threat,” said Patrik Runald, senior manager of security research, Websense. “Criminals know how to take advantage of disasters and the hottest news items to get people to click on infected links. Tragedy is just one type of news that the bad guys use to exploit, compromise and infect your computer. Videos are an especially popular lure; we saw the same thing when Osama bin Laden died and when Casey Anthony was acquitted. During times of crisis or breaking news, your best bet is to stick with the largest news organizations you trust. Avoid the potentially dangerous halls of search engines and social media sites, which are more susceptible to compromise.

20 July 2011

Facebook scammers use Tumblr sites to evade detection

Facebook users are targeted once again by survey scammers, and this time the lure is a video of a woman exposing herself on live television:


There are two versions of the scam. In one, when the user clicks on the play button on the destination page, his click is hijacked and used to "like" the page. In the other, the user is asked to confirm that he is an adult by clicking on the "Jaa" button which actually shares the link with his friends.

"To ensure that this scam continues, the scammers are using Tumblr sites to redirect users to the same Fake YouTube page," explains researcher Satnam Narang. "By redirecting users via Tumblr, the scammers can evade Facebook filters as well as stay off the radar of Facebook’s recent Web of Trust integration."

Other than that, this scam ends on a familiar note - the user is encouraged to fill out surveys in order to get a gift.

Since Facebook still seems to have trouble spotting these types of scams, Narang suggests users to aid the security team by reporting this post if they spot it on their friends' Walls.

15 July 2011

Google+ related scams move to Facebook

Scammers continue to take advantage of the great interest raised by the introduction of Google+ and have begun tricking Facebook users into giving them access to their accounts via a rogue application.

Users are lured in by updates on their news feeds seemingly posted by their friends, which "like" the "Google+ - Get Invite" Facebook page. Clicking on the link gets them to said page, where the rogue app by the name "Google Plus - Direct Access" is linked.

Clicking on the link initiates the request for permissions from the app:


There are people who will become suspicious once they see that the app wants to post things on their Wall, have access to their data at any time and be able to send them emails, but there are obviously still a lot of users who fall for these kind of scams.

Once the permission is given, the victim is urged to "like" the page that propagates the app and is encouraged to send and invite to his friends to visit it - in the hope that they will fall more easily for the scam if a friend of theirs appears to be supporting it.

When all this is done, the user is redirected to the official Google+ homepage. But, if he tries to sign-in, he is faced with the notice that the service has currently exceeded capacity.

Researcher Satnam Narang believes that one of the scammers' goals is to build a list of fresh e-mail accounts that may either be sold or used in future scams, but is also quite likely that once the access to victims' accounts will be misused to spread other scams and/or malicious links.

If you have fallen for this scam, be sure to revoke the permissions you gave the rogue app, delete all mentions of it from your account and warn your friends about it. It is also a very good idea to report the scammy page to Facebook by going to the page and selecting the "report page" link.

25 June 2011

Facebook scam baits users with LulzSec suspect photo

Attention to all Facebook users, here's another FB scam bait. Refrain from clicking on the fake links, it doesn't lead you anywhere.

As the hunt for individuals behind LulzSec is underway, and reports about these worldwide efforts spilled over into the mainstream news, cyber crooks have jumped on the opportunity to misuse the curiosity of the public and have set up a Facebook scam targeting them:


The scam was revealed by Sophos' Graham Cluley when he received a request from a British journalist to share the photo of the recently arrested Essex hacker that is thought to have links with the hacking group.

Cluley said to the journalist that he didn't have the photo in question, but the journalist insisted: "But you do have a photo of the hacker! I've seen it on Facebook! But we want an unblurred version!"

This statement led him to investigate the matter, and he unearthed the above pictured scheme. Sure enough, the link used in the story was one who pointed to Cluley's blog post - but the story didn't include a picture of the suspect.

Following the link to the page in question and to the tab labelled "The Picture", he found out that the scam required the victims to "like" and "share" the page before supposedly being redirected to the unblurred picture. Once they did it, they got redirected to a third-party webpage where they were urged to download a program that installs a series of toolbars on the victims' browser.

He doesn't mentioned whether the unblurred photo is shown in the end, but he managed to track it down to a Wired article from 2008.