Catching Facebook worms in Russia

Just another Sunday evening – I get to Moscow, check in and naturally go online to Facebook to inform everyone about how my trip went. Not very exciting, right? Wrong. A friend had ‘sent’ me a strange-looking link via Facebook IM. A closer look revealed that it was a link being spread by a new and active Facebook worm. The worm was stealing login credentials – and had already successfully stolen the credentials from thousands of people.

The worm spreads through Facebook instant messenger – just like many other Facebook worms. The message states the following: “Is this you?” followed by a link to the malicious Facebook app. The Facebook application is pretty simple; it loads new content into an iframe. The page which is loaded within the iframe is a simple phishing site: it asks for your Facebook credentials so that you can see some new content. Below is a screenshot of the login page:

I decided to investigate the phishing site a bit more, so I checked for some common directories on the server; directories which could contain more information about the worm and I found a directory which contained the Apache access logs. When analyzing the content of the log file I saw that someone was trying to access a file named acc.txt. I downloaded acc.txt and saw that the file contained stolen accounts: in the first version of acc.txt which I downloaded I saw that the attacker had collected over 3000 accounts! I downloaded the acc.txt at 5-minute intervals, and within 20 minutes, the number of stolen accounts went from 3000 to over 6000.

I immediately contacted the Facebook security team – who responded equally rapidly. The malicious page is down, and the Facebook team is going through their remediation routine.

This phishing attack was very simple and yet thousands of people fell for it!!! My guess is that there are lots of other similar attacks happening as I write this.

So… when you are logged on to Facebook, do NOT trust anything which is sent to you, especially not when it asks for your password or credit card information.

Catching Facebook worms in Russia

Your email address will not be published. Required fields are marked *



APT trends report Q2 2021

This is our latest summary of advanced persistent threat (APT) activity, focusing on significant events that we observed during Q2 2021: attacks against Microsoft Exchange servers, APT29 and APT31 activities, targeting campaigns, etc.

LuminousMoth APT: Sweeping attacks for the chosen few

We recently came across unusual APT activity that was detected in high volumes, albeit most likely aimed at a few targets of interest. Further analysis revealed that the actor, which we dubbed LuminousMoth, shows an affinity to the HoneyMyte group, otherwise known as Mustang Panda.

WildPressure targets the macOS platform

We found new malware samples used in WildPressure campaigns: newer version of the C++ Milum Trojan, a corresponding VBScript variant with the same version number, and a Python script working on both Windows and macOS.

Ferocious Kitten: 6 years of covert surveillance in Iran

Ferocious Kitten is an APT group that has been targeting Persian-speaking individuals in Iran. Some of the TTPs used by this threat actor are reminiscent of other groups, such as Domestic Kitten and Rampant Kitten. In this report we aim to provide more details on these findings.

Subscribe to our weekly e-mails

The hottest research right in your inbox