The Latest in IT Security

New Approach to the Old “Facebook Profile Viewer” Ruse

11
Apr
2013

The truth about the Facebook Profile Viewer is simple: it doesn’t exist.

You can check every Facebook page or app available, but you can be 100% sure that each one that says “See who viewed your profile!” or “Who’s stalking you?” is just a ruse for Facebook users to reveal their passwords or spread spam. How do they do this? Clickjacking is a surefire way. In a typical clickjacking attack, cybercriminals hide malicious content under the guise of legitimate pages and may use malicious JavaScript to load content from third-party sites, all in a few clicks.

But what happens if cybercriminals turn to different and newer techniques? Having users type in commands on their keyboard would be a real game changer. Here’s how:

Ctrl+FB

A closer look at a comment within a spammed wall post showcases the start of a different strategy for spammers this time around.

facebook_profileviewer_1

Once you click the link on the comment box, it will redirect again to Facebook Log in Page with Pinterest.

facebook_profileviewer_2

Once logged in, the site redirects to another malicious URL that claims to be “Official Facebook Profile Viewer.” Clicking the ‘Get Started’ button redirects to image with keyboard shortcuts with instructions for users to carry out.

facebook_profileviewer_3

It then redirects to another page asking to type in another set of keyboard shortcuts for the supposed security check.

Finally, the infection chain results in a malicious survey scam, which is typical of many attacks on social networking sites. We have extensively covered this type of scam in the past, including those that leverage Google Glass, Instagram, and even those found on Tumblr. Sadly, users still fall for this. To avoid this threat, always remember that threats are just lurking on social networking sites and always be cautious when clicking links, even if they come from your contacts. Trend Micro already blocks access to sites related to this threat.

And let me be clear – a legitimate Facebook Profile Viewer doesn’t exist. For now, anyway.

Leave a reply


Categories

FRIDAY, APRIL 19, 2024
WHITE PAPERS

Mission-Critical Broadband – Why Governments Should Partner with Commercial Operators:
Many governments embrace mobile network operator (MNO) networks as ...

ARA at Scale: How to Choose a Solution That Grows With Your Needs:
Application release automation (ARA) tools enable best practices in...

The Multi-Model Database:
Part of the “new normal” where data and cloud applications are ...

Featured

Archives

Latest Comments