Incidents

Disliking Facebook LikeJacking

Another Facebook likejacking attempt is being spammed out to fool Facebook users with “5 things girls do before she meets her boyfriend”. Instead of presenting a video, the page redirects browsers to a “Like” button hosted on Facebook.

As illustrated above, tens of thousands of people have clicked on the link while they are logged into Facebook already. If you are one of the people who have already attempted to watch the video, please remove the “like” entry from your wall or newsfeed. Also, delete the liked page from your “Likes and Interests” section.

If you are using Facebook, be wary of what you click on. While this one may not be as serious an issue as some of the other Facebook scams we have seen, you probably don’t want to provide this plugin developer with more demographic statistics of who falls for phony videos.

Even more interesting information falls out when you investigate a bit deeper. Attempting to access the “HTML source” results in an offer suggesting that you sell your fan pages to a suspicious email address, which is not recommended.

Disliking Facebook LikeJacking

Your email address will not be published. Required fields are marked *

 

Reports

Focus on DroxiDat/SystemBC

An unknown actor targeted an electric utility in southern Africa with Cobalt Strike beacons and DroxiDat, a new variant of the SystemBC payload. We speculate that this incident was in the initial stages of a ransomware attack.

APT trends report Q2 2023

This is our latest summary of the significant events and findings, focusing on activities that we observed during Q2 2023.

Meet the GoldenJackal APT group. Don’t expect any howls

GoldenJackal is an APT group, active since 2019, that usually targets government and diplomatic entities in the Middle East and South Asia. The main feature of this group is a specific toolset of .NET malware, JackalControl, JackalWorm, JackalSteal, JackalPerInfo and JackalScreenWatcher.

Subscribe to our weekly e-mails

The hottest research right in your inbox