{"id":9900,"date":"2017-09-11T10:44:35","date_gmt":"2017-09-11T17:44:35","guid":{"rendered":"https:\/\/blog.hellotech.com\/?p=9900"},"modified":"2021-06-11T11:37:39","modified_gmt":"2021-06-11T18:37:39","slug":"facebook-messenger-malware","status":"publish","type":"post","link":"https:\/\/www.hellotech.com\/blog\/facebook-messenger-malware","title":{"rendered":"Beware: Facebook Messenger Malware Begins to Spread"},"content":{"rendered":"\n<p>Did a random friend send you an intriguing link from out of nowhere? Tread with caution because that might just be Facebook Messenger malware in disguise. It looks like cyber felons are at it again. This time, they\u2019re using Facebook Messenger to spread adware and dupe victims with suspicious redirections to fake versions of popular websites.<\/p>\n\n\n\n<p>It\u2019s no ordinary ploy, though. This particular adware campaign uses social engineering to trick victims into installing malware.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-multi-platform-facebook-messenger-malware\">Multi-Platform Facebook Messenger Malware<\/h2>\n\n\n\n<p>A security researcher at Kaspersky Lab, David Jacoby, uncovered a malware attack after receiving a suspicious Facebook message (from a contact). The message, according to his analysis, served a multi-platform malware\/adware that uses tons of domains to prevent tracking and earn clicks.<\/p>\n\n\n\n<p>He suggests the malicious messages are sent from Messenger accounts that have already been compromised. Meaning, those accounts may have already had their credentials stolen or their browsers hijacked.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-cleverly-disguised-attack\">Cleverly Disguised Attack<\/h2>\n\n\n\n<p>David admits that the code behind the spreading Facebook Messenger malware is advanced and obfuscated. The initial attack is fairly simple, though.<\/p>\n\n\n\n<p>A user is sent a message by someone they presumably know. If the potential victim knows the sender well, it\u2019s highly likely he or she may trust what was sent. Once they make the mistake of clicking the attached link (the content often in the form of memes, videos, and other juicy content), the problem begins.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-the-facebook-messenger-malware-attack-deconstructed\">The Facebook Messenger Malware Attack Deconstructed<\/h2>\n\n\n\n<p>In David Jacoby\u2019s documented attack, he reports getting sent a message saying \u201cDavid Video\u201d. Potential victims, indeed, are sent a message composed of their name, the word \u201cVideo\u201d, and a shocked emoji face.<\/p>\n\n\n\n<p>The message often contains a shortened URL that leads to a Google Doc, which shows a blurred photo taken from the person\u2019s FB profile. The said content is usually made to look like a playable movie.<\/p>\n\n\n\n<p>Once the victim bites the bait, the malware sends him\/her to one among a number of different websites, depending on their operating system (OS), browser, location, and other variables. Upon arriving at the intended destination, the landing site will tempt the target to install a disguised adware.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-varied-point-of-attack\">Varied Point of Attack<\/h2>\n\n\n\n<p>The Facebook Messenger malware exhibits uncanny complexity as it will attack various users differently. It deploys a variety of strategy, depending on the user\u2019s OS.<\/p>\n\n\n\n<p>A Safari user will be directed to a site showing a bogus Flash Update. He or she may then be offered to download a .dmg file, which is actually adware. Similarly, Firefox users are brought to a website displaying a fake Flash Update notice. If the user falls for the ruse, the malware will run a Windows executable to deliver the adware.<\/p>\n\n\n\n<p>Google Chrome users, on the other hand, are sent to a portal that closely resembles YouTube. The bogus site comes complete with the official logo and branding, too. It sure can easily fool anyone who doesn\u2019t pay close attention to the URL. They\u2019re then served a fake error message that\u2019ll download a malicious Chrome extension when clicked.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-a-moneymaking-scheme\">A Moneymaking Scheme<\/h2>\n\n\n\n<p>Machines compromised by the adware will risk having their browser activity tracked (via cookies). The same computers will be used to display targeted ads all over the WWW, too. In some cases, the adverts will even use social engineering to dupe potential victims into clicking them.<\/p>\n\n\n\n<p>Keep in mind that every click on those ads will generate revenue for the mastermind of this unscrupulous ploy. And judging by the sheer number of Facebook Messenger users (1.2. billion users in a month), the guy has more than enough target to make a fortune in a short span of time.<\/p>\n\n\n\n<p>Jacoby, nevertheless, surmised that the brains behind this Facebook Messenger malware may already be making a ton of money as it is. Not only that, they are getting access to a lot of FB accounts, too. Unfortunately, there\u2019s little information about this shady campaign and those behind it.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-facebook-s-response\">Facebook\u2019s Response<\/h2>\n\n\n\n<p>In the light of such alarming news, a Facebook spokesperson issued this statement: \u201cWe maintain a number of automated systems to help stop harmful links and files from appearing on Facebook.\u201d<\/p>\n\n\n\n<p>\u201cIf we suspect your computer is infected with malware, we will provide you with a free antivirus scan from our trusted partners,\u201d the statement says. \u201cWe share tips on how to stay secure and links to these scanners on <a href=\"https:\/\/www.facebook.com\/help\">facebook.com\/help<\/a>.\u201d<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-staying-safe-on-facebook\">Staying Safe on Facebook<\/h2>\n\n\n\n<p>No doubt, the social media platform is a great avenue to connect with friends and share content. Remember, though, that malware has infiltrated its vast halls and anyone could fall victim to their cleverly made traps.<\/p>\n\n\n\n<p>To keep malicious software at bay while you&#8217;re on Facebook, heed these precautionary measures:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-mind-everything-you-click\">Mind everything you click<\/h3>\n\n\n\n<p id=\"h-ipad-giveaways-billionaires-sharing-a-fortune-via-chain-emails-or-pornographic-links-click-baits-like-these-are-often-the-work-of-malware-use-your-common-sense-and-resist-clicking-on-anything-too-good-to-be-true\">iPad giveaways, billionaires sharing a fortune (via chain emails), or pornographic links\u2014click-baits like these are often the work of malware. Use your common sense and resist clicking on anything too good to be true.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Review the permissions an app asks for<\/h3>\n\n\n\n<p>Most websites nowadays allow you to use FB credentials to log in. As convenient as this might be in practice, don\u2019t trust every app that asks you to authorize access to your account because many of them are scammers and rogue applications in disguise.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Limit your friends list to people you know<\/h3>\n\n\n\n<p>Don\u2019t be too quick to accept friend requests from complete strangers. If you opened your doors to junk accounts, they could be posting shady links on your wall or sending you malicious content. Keep your circle small and tightly knit.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Have 2FA feature turned on<\/h3>\n\n\n\n<p>Keeping your account secure is the best way to protect your account (as well as your friends) from malware\/adware infections. An easy way to do this is to turn on two-factor authentication (2FA), which is a security method that requires a two-step process to prove your identity. It may be a little hassle going through it every time, but you\u2019d rather be flustered than compromised.<\/p>\n\n\n\n<p>Has an old pal sent you a suspicious link on Facebook Messenger? Tell them their account may be compromised. By keeping an eye out for everyone you know, we all do our part to foil every mischievous ploy crooks put out there.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Did a random friend send you an intriguing link from out of nowhere? Tread with caution because that might just be Facebook Messenger malware in disguise. It looks like cyber felons are at it again. This time, they\u2019re using Facebook Messenger to spread adware and dupe victims with suspicious redirections to fake versions of popular websites. It\u2019s no ordinary ploy, though. This particular adware campaign uses social engineering to trick victims into installing malware. Multi-Platform Facebook Messenger Malware A security [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":9936,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[17587,17593],"tags":[],"class_list":["post-9900","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","category-staying-safe"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v20.10 (Yoast SEO v20.10) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Beware: Facebook Messenger Malware Begins to Spread - The Plug - HelloTech<\/title>\n<meta name=\"description\" content=\"Did a random friend send you an intriguing link from out of nowhere? Tread with caution because that might just be Facebook Messenger malware in disguise.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hellotech.com\/blog\/facebook-messenger-malware\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Beware: Facebook Messenger Malware Begins to Spread - The Plug - HelloTech\" \/>\n<meta property=\"og:description\" content=\"Did a random friend send you an intriguing link from out of nowhere? Tread with caution because that might just be Facebook Messenger malware in disguise.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hellotech.com\/blog\/facebook-messenger-malware\" \/>\n<meta property=\"og:site_name\" content=\"The Plug - HelloTech\" \/>\n<meta property=\"article:publisher\" content=\"http:\/\/www.facebook.com\/hellotech\" \/>\n<meta property=\"article:published_time\" content=\"2017-09-11T17:44:35+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-06-11T18:37:39+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hellotech.com\/blog\/wp-content\/uploads\/2017\/09\/messengermalware-min.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"640\" \/>\n\t<meta property=\"og:image:height\" content=\"426\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@HelloTech\" \/>\n<meta name=\"twitter:site\" content=\"@HelloTech\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.hellotech.com\/blog\/facebook-messenger-malware#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.hellotech.com\/blog\/facebook-messenger-malware\"},\"author\":{\"name\":\"admin\",\"@id\":\"https:\/\/www.hellotech.com\/blog\/#\/schema\/person\/dec00225dd888a509740ace5e4d9de6c\"},\"headline\":\"Beware: Facebook Messenger Malware Begins to Spread\",\"datePublished\":\"2017-09-11T17:44:35+00:00\",\"dateModified\":\"2021-06-11T18:37:39+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.hellotech.com\/blog\/facebook-messenger-malware\"},\"wordCount\":1052,\"publisher\":{\"@id\":\"https:\/\/www.hellotech.com\/blog\/#organization\"},\"articleSection\":[\"News\",\"Staying Safe\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.hellotech.com\/blog\/facebook-messenger-malware\",\"url\":\"https:\/\/www.hellotech.com\/blog\/facebook-messenger-malware\",\"name\":\"Beware: Facebook Messenger Malware Begins to Spread - The Plug - HelloTech\",\"isPartOf\":{\"@id\":\"https:\/\/www.hellotech.com\/blog\/#website\"},\"datePublished\":\"2017-09-11T17:44:35+00:00\",\"dateModified\":\"2021-06-11T18:37:39+00:00\",\"description\":\"Did a random friend send you an intriguing link from out of nowhere? Tread with caution because that might just be Facebook Messenger malware in disguise.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.hellotech.com\/blog\/facebook-messenger-malware#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.hellotech.com\/blog\/facebook-messenger-malware\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.hellotech.com\/blog\/facebook-messenger-malware#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.hellotech.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Beware: Facebook Messenger Malware Begins to Spread\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.hellotech.com\/blog\/#website\",\"url\":\"https:\/\/www.hellotech.com\/blog\/\",\"name\":\"The Plug - HelloTech\",\"description\":\"Turn to The Plug for informative tech news that you can use. \",\"publisher\":{\"@id\":\"https:\/\/www.hellotech.com\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.hellotech.com\/blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.hellotech.com\/blog\/#organization\",\"name\":\"HelloTech\",\"url\":\"https:\/\/www.hellotech.com\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.hellotech.com\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.hellotech.com\/blog\/wp-content\/uploads\/2018\/11\/HT-logo-revised-final.png\",\"contentUrl\":\"https:\/\/www.hellotech.com\/blog\/wp-content\/uploads\/2018\/11\/HT-logo-revised-final.png\",\"width\":1000,\"height\":174,\"caption\":\"HelloTech\"},\"image\":{\"@id\":\"https:\/\/www.hellotech.com\/blog\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"http:\/\/www.facebook.com\/hellotech\",\"https:\/\/twitter.com\/HelloTech\",\"http:\/\/www.instagram.com\/hello_tech\",\"https:\/\/www.youtube.com\/channel\/UCIR-fbAKRfVuAbciDr2z4nQ\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.hellotech.com\/blog\/#\/schema\/person\/dec00225dd888a509740ace5e4d9de6c\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.hellotech.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/cbb537d18df244ad7d57a3639d94ede5cd90bf1fb742392af5731beaf11ffeb1?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/cbb537d18df244ad7d57a3639d94ede5cd90bf1fb742392af5731beaf11ffeb1?s=96&d=mm&r=g\",\"caption\":\"admin\"}}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Beware: Facebook Messenger Malware Begins to Spread - The Plug - HelloTech","description":"Did a random friend send you an intriguing link from out of nowhere? Tread with caution because that might just be Facebook Messenger malware in disguise.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hellotech.com\/blog\/facebook-messenger-malware","og_locale":"en_US","og_type":"article","og_title":"Beware: Facebook Messenger Malware Begins to Spread - The Plug - HelloTech","og_description":"Did a random friend send you an intriguing link from out of nowhere? Tread with caution because that might just be Facebook Messenger malware in disguise.","og_url":"https:\/\/www.hellotech.com\/blog\/facebook-messenger-malware","og_site_name":"The Plug - HelloTech","article_publisher":"http:\/\/www.facebook.com\/hellotech","article_published_time":"2017-09-11T17:44:35+00:00","article_modified_time":"2021-06-11T18:37:39+00:00","og_image":[{"width":640,"height":426,"url":"https:\/\/www.hellotech.com\/blog\/wp-content\/uploads\/2017\/09\/messengermalware-min.jpg","type":"image\/jpeg"}],"author":"admin","twitter_card":"summary_large_image","twitter_creator":"@HelloTech","twitter_site":"@HelloTech","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.hellotech.com\/blog\/facebook-messenger-malware#article","isPartOf":{"@id":"https:\/\/www.hellotech.com\/blog\/facebook-messenger-malware"},"author":{"name":"admin","@id":"https:\/\/www.hellotech.com\/blog\/#\/schema\/person\/dec00225dd888a509740ace5e4d9de6c"},"headline":"Beware: Facebook Messenger Malware Begins to Spread","datePublished":"2017-09-11T17:44:35+00:00","dateModified":"2021-06-11T18:37:39+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hellotech.com\/blog\/facebook-messenger-malware"},"wordCount":1052,"publisher":{"@id":"https:\/\/www.hellotech.com\/blog\/#organization"},"articleSection":["News","Staying Safe"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.hellotech.com\/blog\/facebook-messenger-malware","url":"https:\/\/www.hellotech.com\/blog\/facebook-messenger-malware","name":"Beware: Facebook Messenger Malware Begins to Spread - The Plug - HelloTech","isPartOf":{"@id":"https:\/\/www.hellotech.com\/blog\/#website"},"datePublished":"2017-09-11T17:44:35+00:00","dateModified":"2021-06-11T18:37:39+00:00","description":"Did a random friend send you an intriguing link from out of nowhere? Tread with caution because that might just be Facebook Messenger malware in disguise.","breadcrumb":{"@id":"https:\/\/www.hellotech.com\/blog\/facebook-messenger-malware#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hellotech.com\/blog\/facebook-messenger-malware"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.hellotech.com\/blog\/facebook-messenger-malware#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hellotech.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Beware: Facebook Messenger Malware Begins to Spread"}]},{"@type":"WebSite","@id":"https:\/\/www.hellotech.com\/blog\/#website","url":"https:\/\/www.hellotech.com\/blog\/","name":"The Plug - HelloTech","description":"Turn to The Plug for informative tech news that you can use. ","publisher":{"@id":"https:\/\/www.hellotech.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hellotech.com\/blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hellotech.com\/blog\/#organization","name":"HelloTech","url":"https:\/\/www.hellotech.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hellotech.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.hellotech.com\/blog\/wp-content\/uploads\/2018\/11\/HT-logo-revised-final.png","contentUrl":"https:\/\/www.hellotech.com\/blog\/wp-content\/uploads\/2018\/11\/HT-logo-revised-final.png","width":1000,"height":174,"caption":"HelloTech"},"image":{"@id":"https:\/\/www.hellotech.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["http:\/\/www.facebook.com\/hellotech","https:\/\/twitter.com\/HelloTech","http:\/\/www.instagram.com\/hello_tech","https:\/\/www.youtube.com\/channel\/UCIR-fbAKRfVuAbciDr2z4nQ"]},{"@type":"Person","@id":"https:\/\/www.hellotech.com\/blog\/#\/schema\/person\/dec00225dd888a509740ace5e4d9de6c","name":"admin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hellotech.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/cbb537d18df244ad7d57a3639d94ede5cd90bf1fb742392af5731beaf11ffeb1?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/cbb537d18df244ad7d57a3639d94ede5cd90bf1fb742392af5731beaf11ffeb1?s=96&d=mm&r=g","caption":"admin"}}]}},"_links":{"self":[{"href":"https:\/\/www.hellotech.com\/blog\/wp-json\/wp\/v2\/posts\/9900","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hellotech.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hellotech.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hellotech.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hellotech.com\/blog\/wp-json\/wp\/v2\/comments?post=9900"}],"version-history":[{"count":0,"href":"https:\/\/www.hellotech.com\/blog\/wp-json\/wp\/v2\/posts\/9900\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hellotech.com\/blog\/wp-json\/wp\/v2\/media\/9936"}],"wp:attachment":[{"href":"https:\/\/www.hellotech.com\/blog\/wp-json\/wp\/v2\/media?parent=9900"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hellotech.com\/blog\/wp-json\/wp\/v2\/categories?post=9900"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.hellotech.com\/blog\/wp-json\/wp\/v2\/tags?post=9900"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}