Explorer

New multi- platform adware spreading through Facebook Messenger

New Delhi [India], Aug 28 (ANI): A Kaspersky Lab researcher has discovered new malware, with advanced and obfuscated code, infecting victims with adware through Facebook Messenger.

The initial spreading mechanism seems to be Facebook Messenger, but how it actually spreads via Messenger is still unknown. It may be from stolen credentials, hijacked browsers or clickjacking. At the moment we are not sure because this research is still ongoing.

The message uses traditional social engineering to trick the user into clicking the link. The message reads "David Video" and then a bit.ly link.

When the victim clicks on the fake playable movie, the malware redirects them to a set of websites which enumerate their browser, operating system and other vital information. Depending on their operating system they are directed to other websites.

The malware relies on social engineering for infection, inviting users to click on a link that points to a Google doc. This document has already taken a picture from the victim's Facebook page and created a dynamic landing page which looks like a playable movie.

The adware uses the common "domain chain" technique, redirecting and tracking users through malicious websites depending on characteristics such as language, geo location, operating system, browser information, installed plugins and cookies, etc.

For example, users of different browsers are directed to different landing pages with fake messages and notifications, disguised as updates of popular applications or extensions that can be installed. By clicking on them, adware is downloaded to the victim's device.

The research, which is ongoing, suggests that no actual malware such as Trojans or exploits is being downloaded to devices - although the people behind the malware are likely to be making a lot of money from unsolicited advertising and getting access to many Facebook accounts.

It has been a while since these adware campaigns using Facebook, and its pretty unique that it also uses Google Docs, with customized landing pages. As far as we could see no actual malware (Trojans, exploits) are being downloaded but the people behind this are most likely making a lot of money in ads and getting access to a lot of Facebook accounts. (ANI)


This story has not been edited. It has been published as provided by ANI

View More
Advertisement
Advertisement
25°C
New Delhi
Rain: 100mm
Humidity: 97%
Wind: WNW 47km/h
See Today's Weather
powered by
Accu Weather
Advertisement

Top Headlines

Rahul Gandhi Is Nautankibaaz, Can Never Succeed In Politics: MP Minister Kailash Vijayvargiya. VIDEO
Rahul Gandhi Is Nautankibaaz, Can Never Succeed In Politics: MP Minister Kailash Vijayvargiya
Delhi Air Pollution Still At Alarming Level As Smog Shrouds National Capital, Mumbai Much Cleaner
Delhi Air Pollution Still At Alarming Level As Smog Shrouds National Capital, Mumbai Much Cleaner
Terrorist Killed In Jammu and Kashmir's Bandipora, Operation Kaitsan Underway
Terrorist Killed In Jammu and Kashmir's Bandipora, Operation Kaitsan Underway
Haryana: All-Women SIT Begins Probe Into Sexual Harassment Allegations Against Former Jind SP
Haryana: All-Women SIT Begins Probe Into Sexual Harassment Allegations Against Former Jind SP
Advertisement
ABP Premium

Videos

How will the company perform in Swiggy IPO? It aims to raise Rs 11000 | ABP Paisa LiveDemand will be lowest in last 4 years in 2024 due to rise in gold prices, increased investment in Gold ETFsApple creates a new record in iPhone sales after launch of iPhone 16 | ABP Paisa LiveIs China scared of Gautam Adani's Mega Project In Bhutan? Watch To Find Out | ABP Paisa Live
Embed widget