{"id":12275,"date":"2018-05-12T10:45:03","date_gmt":"2018-05-12T18:45:03","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2018\/05\/12\/news-6044\/"},"modified":"2018-05-12T10:45:03","modified_gmt":"2018-05-12T18:45:03","slug":"news-6044","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2018\/05\/12\/news-6044\/","title":{"rendered":"Russia-Linked Facebook Ads Targeted a Sketchy Chrome Extension at Teen Girls"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/5af614f7b6133764df488088\/master\/pass\/russia_malware_facebook_chrome_extensions-FINAL.jpg\"\/><\/p>\n<p><strong>Credit to Author: Issie Lapowsky| Date: Sat, 12 May 2018 12:40:08 +0000<\/strong><\/p>\n<p><span class=\"lede\">Earlier this week, <\/span>the Democrats on the House Intelligence Committee <a href=\"https:\/\/www.wired.com\/story\/house-democrats-release-3500-russia-linked-facebook-ads\/\">released roughly 3,500 Facebook and Instagram ads<\/a> purchased by the Internet Research Agency, a notorious Russian troll farm. Among them: Ads purchased in May of 2016 that promoted a suspicious Chrome extension that gained wide access to the Facebook accounts and web browsing behavior of those who installed it.<\/p>\n<p>The ads, dozens in total, prompted users to install the extension, a music app called FaceMusic; when they did, some users reported that it began messaging all of their Facebook friends. The landing page for the ads, musicfb.info, was <a href=\"https:\/\/whois.icann.org\/en\/lookup?name=musicfb.info\" target=\"_blank\">registered<\/a> in April of 2016 in St. Petersburg, Russia, where the IRA is based.<\/p>\n<p class=\"paywall\">The most successful ad, which yielded 28 clicks, specifically targeted American girls, ages 14 to 17, who Facebook classified as interested in free software and music. Other ads for FaceMusic targeted interest categories like Shazam, Spotify, Apple Music, or Soundcloud.<\/p>\n<p class=\"paywall\">The ads containing the extension, purchased by the IRA&#x27;s phony anti-immigrant Facebook page Stop All Invaders, were discovered by Jonathan Albright, director of research at Columbia University&#x27;s Tow Center for Digital Journalism.<\/p>\n<p class=\"paywall\">&quot;Why would an anti-immigrant Russian Facebook Page be spending money to promote a music app?&quot; Albright says.<\/p>\n<p class=\"paywall\">The landing site that the ad directed to, musicfb.info, is no longer active, but an <a href=\"https:\/\/web.archive.org\/web\/20161019155736\/https:\/\/musicfb.info\/\" target=\"_blank\">archived version<\/a> advertises a \u201cunique browser extension, which allows you to play your favorite music on Facebook for free and share it with your friends.\u201d<\/p>\n<p class=\"paywall\">The extension is no longer active in the Chrome Web Store, either, and a Google spokesperson confirmed the company had also removed it from users&#x27; devices. &quot;When we discover malicious extensions, we remove them from the Chrome Web Store and from every user&#x27;s computer that has downloaded them,&quot; the spokesperson said. &quot;We suspend the developer and remove their other extensions from the Store as well.&quot;<\/p>\n<p class=\"paywall\">Facebook could not confirm the number of people who signed into the extension through Facebook. It&#x27;s also unclear how many installed the extension after seeing the IRA&#x27;s Facebook ads. In total, the ads received just over 80 clicks, according to the metadata released by Facebook. Most of the ads received no clicks at all, likely because they had nothing to do with the other content posted by the Stop All Invaders page, which included, among other things, photoshopped <a href=\"https:\/\/www.wired.com\/story\/house-democrats-release-3500-russia-linked-facebook-ads\/\">memes<\/a> calling President Obama &quot;a mere pawn in the hands of the Arabian Sheikhs.&quot;<\/p>\n<p class=\"paywall\">Facebook also wasn\u2019t the only platform where the IRA promoted FaceMusic. A Reddit user named <a href=\"https:\/\/www.reddit.com\/wiki\/suspiciousaccounts\" target=\"_blank\">Rubinjer<\/a>, which Reddit <a href=\"https:\/\/www.wired.com\/story\/reddit-russian-propaganda\/\">has since identified as linked to the IRA<\/a>, also <a href=\"https:\/\/www.reddit.com\/r\/UsefulWebsites\/comments\/4j0vtb\/with_this_service_you_can_find_listen_to_and_send\/\" target=\"_blank\">posted<\/a> it to the subreddit r\/UsefulWebsites.<\/p>\n<p class=\"paywall\">Though the extension has been removed from the Chrome Web Store, J\u00e9r\u00f4me Segura, a researcher at the security firm Malwarebytes Labs, found an archived version of FaceMusic and installed it manually. He found that the extension asked users for permission to &quot;read and change all your data on the websites you visit, display notifications, and modify data you copy and paste.&quot;<\/p>\n<p class=\"paywall\">It also had permission to post to users\u2019 Facebook timelines and message their friends. It apparently took full advantage. In June of 2016, a month after the IRA\u2019s ads went live, one user took to the online photo-sharing site Imgur to complain that FaceMusic had spammed their friends with Facebook messages. &quot;Facemusic sent a direct link to download their extension, to 100+ of my friends,&quot; the <a href=\"https:\/\/imgur.com\/gallery\/OahBl\" target=\"_blank\">user wrote<\/a>. &quot;PLEASE, DO NOT GET &#x27;Facemusic&#x27;!!! If you have it, GET RID OF IT IMMEDIATELY, change your FB password, and [perform] a virus scan.&quot; Several other users responded that the same had happened to them.<\/p>\n<p class=\"paywall\">&quot;We\u2019ve seen examples of using a lure, like a music app or a game, for other purposes,&quot; says Segura. He notes, though, that the extension itself doesn&#x27;t seem to contain malicious code, and received a clean bill of health from more than 50 antivirus engines. Instead, it used Facebook and Google&#x27;s generous permissions to access users&#x27; data and message their friends.<\/p>\n<p class=\"paywall\">Segura says that these permissions, while broad, are fairly standard for Chrome extensions, which often overreach the boundaries of privacy.  &quot;They have too many privileges. You download a game and all you want is the game, but the game wants contacts from your phone,&quot; he says. In the hands of a group like the IRA, that kind of unchecked power can go very wrong.<\/p>\n<p class=\"related-cne-video-component__dek\">Alex Jones is not the only guy making a career out of conspiracy theories. They are everywhere on the internet and here&#39;s why you have no choice but to ignore them.<\/p>\n<p><a href=\"https:\/\/www.wired.com\/story\/russia-facebook-ads-sketchy-chrome-extension\" target=\"bwo\" >https:\/\/www.wired.com\/category\/security\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/5af614f7b6133764df488088\/master\/pass\/russia_malware_facebook_chrome_extensions-FINAL.jpg\"\/><\/p>\n<p><strong>Credit to Author: Issie Lapowsky| Date: Sat, 12 May 2018 12:40:08 +0000<\/strong><\/p>\n<p>Among the Russian ads released by House Democrats this week were links promoting malicious Chrome extensions.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10607],"tags":[714],"class_list":["post-12275","post","type-post","status-publish","format-standard","hentry","category-security","category-wired","tag-security"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/12275","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=12275"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/12275\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=12275"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=12275"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=12275"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}