New multi- platform adware spreading through Facebook Messenger

Image
ANI New Delhi [India]
Last Updated : Aug 28 2017 | 4:07 PM IST

A Kaspersky Lab researcher has discovered new malware, with advanced and obfuscated code, infecting victims with adware through Facebook Messenger.

The initial spreading mechanism seems to be Facebook Messenger, but how it actually spreads via Messenger is still unknown. It may be from stolen credentials, hijacked browsers or clickjacking. At the moment we are not sure because this research is still ongoing.

The message uses traditional social engineering to trick the user into clicking the link. The message reads "David Video" and then a bit.ly link.

When the victim clicks on the fake playable movie, the malware redirects them to a set of websites which enumerate their browser, operating system and other vital information. Depending on their operating system they are directed to other websites.

The malware relies on social engineering for infection, inviting users to click on a link that points to a Google doc. This document has already taken a picture from the victim's Facebook page and created a dynamic landing page which looks like a playable movie.

The adware uses the common "domain chain" technique, redirecting and tracking users through malicious websites depending on characteristics such as language, geo location, operating system, browser information, installed plugins and cookies, etc.

For example, users of different browsers are directed to different landing pages with fake messages and notifications, disguised as updates of popular applications or extensions that can be installed. By clicking on them, adware is downloaded to the victim's device.

The research, which is ongoing, suggests that no actual malware such as Trojans or exploits is being downloaded to devices - although the people behind the malware are likely to be making a lot of money from unsolicited advertising and getting access to many Facebook accounts.

It has been a while since these adware campaigns using Facebook, and its pretty unique that it also uses Google Docs, with customized landing pages. As far as we could see no actual malware (Trojans, exploits) are being downloaded but the people behind this are most likely making a lot of money in ads and getting access to a lot of Facebook accounts.

Disclaimer: No Business Standard Journalist was involved in creation of this content

*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

First Published: Aug 28 2017 | 4:07 PM IST

Next Story