{"id":23720,"date":"2024-01-16T04:10:25","date_gmt":"2024-01-16T12:10:25","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2024\/01\/16\/news-17450\/"},"modified":"2024-01-16T04:10:25","modified_gmt":"2024-01-16T12:10:25","slug":"news-17450","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2024\/01\/16\/news-17450\/","title":{"rendered":"\u201cI&#8217;ll miss him so much\u201d Facebook scam uses BBC branding to lure victims"},"content":{"rendered":"\n<p>Facebook scams are a constant nuisance and vary from <a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2019\/04\/explained-like-farming\">like-farming<\/a> to scams that can cost you some serious money. The latest one we found is a bit morbid.<\/p>\n<p>Recently, I\u2019ve seen quite a few posts on my timeline that looked like this:<\/p>\n<figure class=\"wp-block-image aligncenter size-full is-resized\"><img decoding=\"async\" loading=\"lazy\" width=\"748\" height=\"200\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/01\/Facebook_scam_redacted.jpg\" alt=\"I can't believe he's gone. I'll miss him so much\" class=\"wp-image-102167\" style=\"width:700px\" \/><\/figure>\n<p>Without going into details the post says:<\/p>\n<blockquote class=\"wp-block-quote\">\n<p>\u201cI can\u2019t believe he\u2019s gone. I\u2019ll miss him so much\u201d<\/p>\n<\/blockquote>\n<p>In all the posts I&#8217;ve seen, one of my Facebook friends was tagged. When I noticed that happen to two friends that do not know each other, the post did what it was intended to do, trigger my curiosity.<\/p>\n<p>When you follow the posted link, which is a Facebook permalink to a post made by what is probably a compromised account, you\u2019ll see a fake BBC news item about a fatal road accident. The permalink of any post on Facebook is hidden under its time stamp and can be used to share content on or outside of Facebook.<\/p>\n<p>This post features a slightly different text: \u201cI can\u2019t believe this, I\u2019m going to miss him so much\u201d<\/p>\n<figure class=\"wp-block-image aligncenter size-full is-resized\"><img decoding=\"async\" loading=\"lazy\" width=\"683\" height=\"578\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/01\/fake-BBC-news-item.jpg\" alt=\"I can\u2019t believe this, I\u2019m going to miss him so much above a fake BBC news item about a fatal road accident\" class=\"wp-image-102168\" style=\"width:700px\" \/><\/figure>\n<p>The BBC news logo in the picture and the BBCNEWS part of the URL are obviously intended to gain your trust, and suggest that it\u2019s safe to play the video.<\/p>\n<p>In reality you will be redirected to the link displayed directly below the movie. We found several variations of that URL. All composed like this \u201cBBCNEWS-{6 characters}.OMH4.XYZ\u201d<\/p>\n<p>Clicking the play button takes you through several redirects, very likely to perform fingerprinting, where sites gather information about your browser, your location, and other sites you\u2019ve visited. The scammers do this to make sure you are redirected to a site that is likely to generate the most profit from people fitting your profile.<\/p>\n<p>During my testing,&nbsp;I was not logged in on Facebook and surfing from a Dutch IP address, I ended up at polo[.]thegadgetguru[.]club which was unreachable at the time of writing. However, our <a href=\"https:\/\/www.malwarebytes.com\/blog\/detections\/thegadgetguru-club\">archives<\/a> show it\u2019s a known source of pop-ups and has been for at least two years. These pop-ups can lead visitors to <a href=\"https:\/\/www.malwarebytes.com\/cybersecurity\/basics\/what-is-pup\">potentially unwanted programs<\/a>, <a href=\"https:\/\/www.malwarebytes.com\/blog\/threats\/adware\">adware<\/a>, and fraudulent sites.<\/p>\n<figure class=\"wp-block-image aligncenter size-full is-resized\"><img decoding=\"async\" loading=\"lazy\" width=\"823\" height=\"532\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/01\/thegadgetguruclubblock.png\" alt=\"\" class=\"wp-image-102169\" style=\"width:700px\" \/><\/figure>\n<p>It&#8217;s very likely that changing my IP address to a different location with a VPN and logging in to Facebook will change the outcome of the redirects, but I\u2019m pretty sure none of them will be up to any good.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-how-to-avoid-facebook-scams\">How to avoid Facebook scams<\/h2>\n<p>In this case I was able to spot the scam because it made me suspicious that two unrelated friends might be tagged in a similar post. But there are some other pointers to help you spot Facebook scams.<\/p>\n<ul>\n<li>Scrutinize URLs closely. Not every scam campaign is sophisticated or difficult to spot. Start with the URL \u2013 if it\u2019s obviously not for the website in question then step away.<\/li>\n<li>Reach out to friends and family outside of Facebook or Instagram. If you\u2019re not sure if a message is from the person it says it\u2019s from, give them a call or send them a text message to check they really did send it.<\/li>\n<li>Be wary of \u201cfree\u201d stuff. Sure, free things are nice\u2014but they shouldn\u2019t cost you anything, and that includes your personal details or a small amount of money that you must pay first. If you see a giveaway doing the rounds on Facebook, go to that company\u2019s official webpage to verify it, or give them a call.<\/li>\n<li>Update your browser regularly. This keeps new vulnerabilities at bay, and is another layer of protection you can depend on.<\/li>\n<li>Change your login credentials if you think your account may be compromised. And if you&#8217;ve used the same password on other sites, change them.<\/li>\n<li>Install browser protection, like <a href=\"https:\/\/www.malwarebytes.com\/browserguard\">Malwarebytes Browser Guard<\/a>, which can alert you to scams and other nasties in the browser.<\/li>\n<li>If you\u2019ve decided you\u2019ve had it with Facebook you may like this post on <a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2021\/06\/how-to-deactivate-or-delete-your-facebook-account\">how to deactivate or delete your Facebook account<\/a>.<\/li>\n<\/ul>\n<p>Report any posts you may find that are suspicious, scammy, illegal, or downright harmful to other Facebook users\u2019 wellbeing. You can find this feature by clicking in the upper right hand corner of the Facebook post in question and picking either \u201cReport post\u201d or \u201cReport photo\u201d.<\/p>\n<hr class=\"wp-block-separator has-text-color has-cyan-bluish-gray-color has-alpha-channel-opacity has-cyan-bluish-gray-background-color has-background is-style-wide\" \/>\n<p><strong>We don\u2019t just report on threats\u2014we remove them<\/strong><\/p>\n<p>Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by&nbsp;<a href=\"https:\/\/www.malwarebytes.com\/for-home\">downloading Malwarebytes today<\/a>.<\/p>\n<p><a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2024\/01\/ill-miss-him-so-much-facebook-scam-uses-bbc-branding-to-lure-victims\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> We found a Facebook scam that aims to redirect victims to sites promoting PUPs, adware, or other fraudulent sites. <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[30715,3589,29378,30716,32,26699],"class_list":["post-23720","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-cant-believe","tag-facebook","tag-fake-bbc-news","tag-miss-him-so-much","tag-news","tag-personal"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/23720","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=23720"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/23720\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=23720"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=23720"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=23720"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}