{"id":12006,"date":"2018-04-13T08:10:08","date_gmt":"2018-04-13T16:10:08","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2018\/04\/13\/news-5775\/"},"modified":"2018-04-13T08:10:08","modified_gmt":"2018-04-13T16:10:08","slug":"news-5775","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2018\/04\/13\/news-5775\/","title":{"rendered":"Facebook spammers making things worse"},"content":{"rendered":"<p><strong>Credit to Author: Pieter Arntz| Date: Fri, 13 Apr 2018 15:00:00 +0000<\/strong><\/p>\n<p>Facebook&#8217;s having a bad couple of weeks. Between Congressional testimony and new information coming forward about <a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/03\/what-facebooks-cambridge-analytica-problem-means-for-your-data\/\" target=\"_blank\" rel=\"noopener\">Cambridge Analytica&#8217;s use of user data<\/a>, the tech giant is having\u00a0<a href=\"http:\/\/www.news.com.au\/technology\/online\/social\/facebook-users-are-deleting-their-accounts-after-it-was-revealed-their-data-was-used-in-the-2016-us-election\/news-story\/41a355e6846865ba37525624a98e2fb0\" target=\"_blank\" rel=\"noopener\">problems keeping its users aboard<\/a>. Unfortunately, misery loves company. We noticed a few Facebook spam campaigns this week that can only make things worse.<\/p>\n<h3>Should a browser extension be able to add a Facebook app?<\/h3>\n<p>The first of the Facebook spammers was pointed out by one of our <a href=\"https:\/\/forums.malwarebytes.com\/profile\/246992-locheed\/\" target=\"_blank\" rel=\"noopener\">forum visitors<\/a>. While the campaign was aimed at Finnish Facebook users, the origin is probably not Finnish, so this one could be coming to a Facebook timeline near you anytime soon.<\/p>\n<p>The modus operandi was like this: A website was set up to install a forced Firefox extension claiming you need a Flash update.<\/p>\n<div id=\"attachment_23134\" style=\"width: 705px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"23134\" data-permalink=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/04\/facebook-spammers-making-things-worse\/attachment\/website-11\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/website.png\" data-orig-size=\"695,441\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"website\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/website-300x190.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/website-600x381.png\" class=\"size-full wp-image-23134\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/website.png\" alt=\"install flash update\" width=\"695\" height=\"441\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/website.png 695w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/website-300x190.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/website-600x381.png 600w\" sizes=\"auto, (max-width: 695px) 100vw, 695px\" \/><\/p>\n<p class=\"wp-caption-text\"><em>Translation: your Flash player has expired, and you need to update in order for the website to work properly. Accept\/install flash updates and add them into your browser.<\/em><\/p>\n<\/div>\n<p>Once installed, the extension looked like this:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"23135\" data-permalink=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/04\/facebook-spammers-making-things-worse\/attachment\/main-31\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/main.png\" data-orig-size=\"624,300\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"main\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/main-300x144.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/main-600x288.png\" class=\"size-full wp-image-23135 aligncenter\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/main.png\" alt=\"Flash paivitys\" width=\"624\" height=\"300\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/main.png 624w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/main-300x144.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/main-600x288.png 600w\" sizes=\"auto, (max-width: 624px) 100vw, 624px\" \/><\/p>\n<p style=\"text-align: center\"><em>Looks legit, right?<\/em><\/p>\n<p>What has this got to do with Facebook, you ask? Users that installed this extension and were logged into Facebook at the same time in the same browser got a bonus: A Facebook app, reportedly using several different names like HTC Sense, Spotify, and Pandora. This app started spamming the user groups the affected Facebook account belonged to with messages like this:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"23125\" data-permalink=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/04\/facebook-spammers-making-things-worse\/attachment\/fbpostoriginal\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/FBpostoriginal.png\" data-orig-size=\"501,196\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"FBpostoriginal\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/FBpostoriginal-300x117.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/FBpostoriginal.png\" class=\"aligncenter size-full wp-image-23125\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/FBpostoriginal.png\" alt=\"Facebook post Finnish\" width=\"501\" height=\"196\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/FBpostoriginal.png 501w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/FBpostoriginal-300x117.png 300w\" sizes=\"auto, (max-width: 501px) 100vw, 501px\" \/><\/p>\n<p>An English version of this post (courtesy of Facebook) would look like this:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"23124\" data-permalink=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/04\/facebook-spammers-making-things-worse\/attachment\/fbpostenglish\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/FBpostEnglish.png\" data-orig-size=\"501,235\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"FBpostEnglish\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/FBpostEnglish-300x141.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/FBpostEnglish.png\" class=\"aligncenter size-full wp-image-23124\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/FBpostEnglish.png\" alt=\"Facebook post English translation\" width=\"501\" height=\"235\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/FBpostEnglish.png 501w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/FBpostEnglish-300x141.png 300w\" sizes=\"auto, (max-width: 501px) 100vw, 501px\" \/><\/p>\n<p>So the <a href=\"https:\/\/blog.malwarebytes.com\/glossary\/threat-actor\/\" target=\"_blank\" rel=\"noopener\">threat actors<\/a> would have you Google a certain key phrase and made sure you ended up at a sponsored result that would offer high-end phones for unbelievable prices. And you know what they say about things that are to good to be true. The top search result for the keyword now goes to a Facebook page warning about this scam:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"23126\" data-permalink=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/04\/facebook-spammers-making-things-worse\/attachment\/scamalert\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/ScamAlert.png\" data-orig-size=\"474,307\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"ScamAlert\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/ScamAlert-300x194.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/ScamAlert.png\" class=\"aligncenter size-full wp-image-23126\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/ScamAlert.png\" alt=\"Scam Alert\" width=\"474\" height=\"307\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/ScamAlert.png 474w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/ScamAlert-300x194.png 300w\" sizes=\"auto, (max-width: 474px) 100vw, 474px\" \/><\/p>\n<p>So, this about sums up how this intricate scheme worked, but the question that kept nagging at me is: Why can a Firefox extension install a Facebook app? Well, that\u2019s a simple matter of permissions.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"23127\" data-permalink=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/04\/facebook-spammers-making-things-worse\/attachment\/warning1-20\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/warning1.png\" data-orig-size=\"360,167\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"warning1\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/warning1-300x139.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/warning1.png\" class=\"aligncenter size-full wp-image-23127\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/warning1.png\" alt=\"extension permissions\" width=\"360\" height=\"167\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/warning1.png 360w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/warning1-300x139.png 300w\" sizes=\"auto, (max-width: 360px) 100vw, 360px\" \/><\/p>\n<p>If you allow extensions to access your data for all websites (in this case, Facebook), even on other tabs, it can \u201cborrow\u201d your login session and install an app for you. Note that the extension needs you to &#8220;auto-login&#8221; to Facebook when it opens Facebook in a new tab (or pop-up).<\/p>\n<p>In the xpi file that is the &#8220;de facto&#8221; Firefox extension, there are two heavily obfuscated JavaScripts called background.js and tokeneo.js. Together, they are able to open a pop-up asking for your permission to install a Facebook app and confirming that action at the same time. All it needs is for you to be logged in to Facebook on one of the other tabs. And most Facebook users will automatically be logged in as soon as they open the site.<\/p>\n<div id=\"attachment_23136\" style=\"width: 610px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/deobfuscated-1.png\" data-rel=\"lightbox-0\" title=\"\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"23136\" data-permalink=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/04\/facebook-spammers-making-things-worse\/attachment\/deobfuscated-2\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/deobfuscated-1.png\" data-orig-size=\"1836,508\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"deobfuscated\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/deobfuscated-1-300x83.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/deobfuscated-1-600x166.png\" class=\"wp-image-23136 size-large\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/deobfuscated-1-600x166.png\" alt=\"partially deobfuscated piece of the extension\" width=\"600\" height=\"166\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/deobfuscated-1-600x166.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/deobfuscated-1-300x83.png 300w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/a><\/p>\n<p class=\"wp-caption-text\"><em>Partially deobfuscated snippet from tokeneo.js<\/em><\/p>\n<\/div>\n<h3>Removal<\/h3>\n<p>Malwarebytes can remove the extension for you, as pointed out in our <a href=\"https:\/\/forums.malwarebytes.com\/topic\/226165-removal-instructions-for-flash-paivitys\/\" target=\"_blank\" rel=\"noopener\">removal guide for Flash-paivitys<\/a>, but you will have to <a href=\"https:\/\/www.facebook.com\/help\/204306713029340\/\" target=\"_blank\" rel=\"noopener\">remove the Facebook app manually<\/a>. Look for the \u00a0names we have mentioned earlier:<\/p>\n<ul>\n<li>HTC Sense<\/li>\n<li>Spotify<\/li>\n<li>Pandora<\/li>\n<\/ul>\n<p>But keep in mind that they can adapt these easily. Rule of thumb for removing Facebook apps: If you can\u2019t recall why you installed it, it should probably not be allowed to post on your behalf. We have reported the API that was used in the extension to Facebook, and they have taken it into consideration. Hopefully it will be blocked soon.<\/p>\n<h3>IOCs<\/h3>\n<p>http:\/\/42760.s.time4vps[.]cloud\/awesomestuff<\/p>\n<p>adsfinland@firefox.pl.xpi<\/p>\n<p>http:\/\/suomic[.]com<\/p>\n<h3>Oh, but there&#8217;s more<\/h3>\n<p>The other campaign that is making the rounds spams your Facebook friends by sending a so-called YouTube link via Messenger.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"23129\" data-permalink=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/04\/facebook-spammers-making-things-worse\/attachment\/fbpm\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/FBpm.png\" data-orig-size=\"245,140\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"FBpm\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/FBpm.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/FBpm.png\" class=\"aligncenter size-full wp-image-23129\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/FBpm.png\" alt=\"Messenger spam\" width=\"245\" height=\"140\" \/><\/p>\n<p>In fact, the link does not take you to YouTube at all, but to: https:\/\/yeral1522930198.storage.googleapis.com\/1522930198.html?wkr=yeral&amp;id={id number}&amp;name={username}<\/p>\n<p>Which only shows this button:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"23132\" data-permalink=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/04\/facebook-spammers-making-things-worse\/attachment\/fbspambutton\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/FBspambutton.png\" data-orig-size=\"266,118\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"FBspambutton\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/FBspambutton.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/FBspambutton.png\" class=\"aligncenter size-full wp-image-23132\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/FBspambutton.png\" alt=\"watch video\" width=\"266\" height=\"118\" \/><\/p>\n<p>Clicking that button takes you to http:\/\/dosmil.puchamon[.]info\/?wkr=manu&amp;id={id number} &amp;name={username}. It looks as if this has been removed by the host, but a look at the archives shows us that it very likely was a page asking for your permission to install yet another Facebook app.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"23133\" data-permalink=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/04\/facebook-spammers-making-things-worse\/attachment\/fbpermission\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/FBpermission.png\" data-orig-size=\"194,327\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"FBpermission\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/FBpermission-178x300.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/FBpermission.png\" class=\"aligncenter size-full wp-image-23133\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/FBpermission.png\" alt=\"confirm to access application\" width=\"194\" height=\"327\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/FBpermission.png 194w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/FBpermission-178x300.png 178w\" sizes=\"auto, (max-width: 194px) 100vw, 194px\" \/><\/p>\n<p>And that app would have just as easily turned you into the next person spreading these Messenger links. This looks a lot like the <a href=\"https:\/\/www.techworm.net\/2017\/08\/facebook-messenger-scam-targeting-victims-via-video-link-malware.html\" target=\"_blank\" rel=\"noopener\">\u201cIs this you?\u201d Messenger campaign<\/a> that made the rounds last year. If they really are related, then the main goal is probably <a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/03\/adware-vs-ad-fraud\/\" target=\"_blank\" rel=\"noopener\">ad fraud<\/a> by clickjacking.<\/p>\n<h3>IOC<\/h3>\n<p>dosmil.puchamon[.]info<\/p>\n<h3>Spam adds to burden<\/h3>\n<p>These two new spam campaigns are only adding to Facebook&#8217;s burden.\u00a0While one is aimed at Finnish users (for now) and the other was rather quickly terminated, we expect both to resurface in one form or another.<\/p>\n<p>If Facebook wants to have a close look at the apps that they allow on their platform, they should start by putting a big dent in the number of apps that are spreading malware, or simply clickfraud, and that propagate by spamming user groups, Messenger inboxes, and timelines in general.<\/p>\n<p>Stay safe, everyone!<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/04\/facebook-spammers-making-things-worse\/\">Facebook spammers making things worse<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/04\/facebook-spammers-making-things-worse\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Pieter Arntz| Date: Fri, 13 Apr 2018 15:00:00 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/04\/facebook-spammers-making-things-worse\/' title='Facebook spammers making things worse'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/facebook-900x506.jpg' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>Adding to Facebook&#8217;s burden\u00a0are two spam campaigns. One is aimed at Finnish users and the other was quickly terminated, but we expect both to resurface in one form or another.<\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/\" rel=\"category tag\">Cybercrime<\/a><\/li>\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/social-engineering-cybercrime\/\" rel=\"category tag\">Social engineering<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/facebook\/\" rel=\"tag\">facebook<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/facebook-messenger\/\" rel=\"tag\">Facebook Messenger<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/finnish\/\" rel=\"tag\">finnish<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/messenger\/\" rel=\"tag\">messenger<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/spam\/\" rel=\"tag\">spam<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/youtube\/\" rel=\"tag\">youtube<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/04\/facebook-spammers-making-things-worse\/' title='Facebook spammers making things worse'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/04\/facebook-spammers-making-things-worse\/\">Facebook spammers making things worse<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[4503,3589,14359,18099,18100,10510,10518,2593],"class_list":["post-12006","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-cybercrime","tag-facebook","tag-facebook-messenger","tag-finnish","tag-messenger","tag-social-engineering","tag-spam","tag-youtube"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/12006","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=12006"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/12006\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=12006"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=12006"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=12006"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}