{"id":19062,"date":"2022-05-17T03:10:13","date_gmt":"2022-05-17T11:10:13","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2022\/05\/17\/news-12795\/"},"modified":"2022-05-17T03:10:13","modified_gmt":"2022-05-17T11:10:13","slug":"news-12795","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2022\/05\/17\/news-12795\/","title":{"rendered":"&#8220;Look what I found here&#8221; phish targets Facebook users"},"content":{"rendered":"<p><strong>Credit to Author: Christopher Boyd| Date: Tue, 17 May 2022 10:54:33 +0000<\/strong><\/p>\n<p>Facebook-themed messages are a frequent source of bogus links from both spam and compromised accounts. Whether you receive the messages via SMS, the Messenger app, or just inside regular web chat, it pays to be careful. A wide variety of attacks use bogus messages as their launchpad, and the risk of account compromise is ever-present. Phishing is not the only threat. Scammers will also happily send \u201ccheck this out\u201d messages and <a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2014\/03\/malicious-messages-foray-facebook\/\">direct you to malware<\/a>. This is why it\u2019s crucial to be careful around links\u2026any link. You just never know.<\/p>\n<p>One such phishing message is currently doing the rounds in Dutch, and it plugs into a sense of <a href=\"https:\/\/www.merriam-webster.com\/dictionary\/FOMO#:~:text=Definition%20of%20FOMO,O.\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">FOMO<\/a> to encourage you to click the link. It was <a href=\"https:\/\/7news.com.au\/news\/cyber-security\/look-what-i-found-phishing-scam-grows-on-facebook-messenger-c-6191588\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">first observed<\/a> back in March, and appears to be making a comeback.<\/p>\n<h2>How does this phish attack work?<\/h2>\n<p>This is the message currently in circulation, being distributed through a compromised account:<\/p>\n<blockquote class=\"wp-block-quote\">\n<p><em>Kijk eens wat ik hier heb gevonden?? [url]<\/em><\/p>\n<\/blockquote>\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"56688\" data-permalink=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/05\/look-what-i-found-here-phish-targets-facebook-users\/attachment\/ifjhyrq9\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/05\/ifjhYrq9.png\" data-orig-size=\"261,154\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"ifjhYrq9\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/05\/ifjhYrq9.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/05\/ifjhYrq9.png\" width=\"261\" height=\"154\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/05\/ifjhYrq9.png\" alt=\"\" class=\"wp-image-56688\" \/><\/figure>\n<p>The message says \u201cLook what I found here\u201d.<\/p>\n<p>This is a very common tactic, not giving anything away and almost baiting you into clicking. There\u2019s a few others along these lines being sent to people in Facebook Messenger at the moment. One style of message is one that asks something along the lines of \u201cHave you seen who died\/Guess who died\u201d. The answer, of course, is nobody has died. However, the aim of the game is to have you panic and hit the link without thinking.<\/p>\n<p>It\u2019s a similar technique in play here, although nowhere remotely as panic-inducing.<\/p>\n<p>All the same, the link redirects to a fake Facebook page on what looks like a compromised photography website.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" data-attachment-id=\"56689\" data-permalink=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/05\/look-what-i-found-here-phish-targets-facebook-users\/attachment\/facebook-messenger-phish\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/05\/facebook-messenger-phish.png\" data-orig-size=\"719,551\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"facebook-messenger-phish\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/05\/facebook-messenger-phish-300x230.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/05\/facebook-messenger-phish-600x460.png\" loading=\"lazy\" width=\"600\" height=\"460\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/05\/facebook-messenger-phish-600x460.png\" alt=\"\" class=\"wp-image-56689\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/05\/facebook-messenger-phish-600x460.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/05\/facebook-messenger-phish-300x230.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/05\/facebook-messenger-phish.png 719w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/figure>\n<\/div>\n<p>The site says \u201cFacebook needs to verify that it\u2019s you, log in to continue\u201d and asks for mobile number\/email and password.<\/p>\n<p>Hitting the login button submits the data and redirects you through several different domains. In testing, we kept hitting a Google 404 error but you may well end up somewhere else depending on region, type of browser, device, and so on.<\/p>\n<p>If you\u2019ve entered your login after clicking through from a random message in this fashion, stop what you\u2019re doing. Go to Facebook and change your password as soon as you possibly can. <\/p>\n<h2>The power of \u201cfriendly\u201d messaging<\/h2>\n<p>The big problem with rogue messages via IM is the aspect of sender trust. If a link is sent to you from a total stranger on a public platform like Twitter, you\u2019ll probably be sceptical and treat it with the caution it deserves. An SMS from a number you don\u2019t recognise? They have some success depending on scam type, but you\u2019d probably expect a banking phish or a fake parcel delivery message through that route.<\/p>\n<p>But if you get a message from someone within your closed network of friends and family, where you may interact dozens or even hundreds of times a day, then it&#8217;s likely you&#8217;ll be clicking those links with a lot more confidence.<\/p>\n<p>Sadly, accounts belonging to those you trust can be hijacked like any others. If your dad\u2019s Facebook account was compromised yesterday and you woke to a link and a message which reads \u201cLook what I found here\u201d, what would you do?<\/p>\n<p>Phishers know that if they can crack an account, it\u2019ll almost certainly be allowed to send messages to people in its immediate circle as their security settings will permit them access. After all, you don\u2019t add your closest relatives to Facebook and then <em>prevent<\/em> them from sending you messages. <\/p>\n<h2>Tips to avoid falling for rogue messages<\/h2>\n<ul>\n<li>Watch out for messages which don\u2019t logically follow on from the natural flow of a conversation, or a few hours after you stopped talking. \u201cThis you\u201d, \u201cHave you seen this photo\u201d, \u201cDid you hear who died\u201d, \u201cOMG I can\u2019t believe it\u201d all tied to a URL should raise some red flags.<\/li>\n<li>If you\u2019re presented with a \u201cLogin to view content\u201d box, question why that is. If you\u2019re on the Facebook website talking to someone and already logged in, there should be no reason why you\u2019d be asked to login again. Check the URL. Does it say Facebook.com? Or is it a totally unrelated domain?<\/li>\n<li>If you have an alternative method of communication with the person who sent you the message, try it. Ask them if they sent you a message on Facebook, and wait for their response before doing anything.<\/li>\n<li>Enable 2-factor authentication (2FA). If you hand over your password to a phishing page, the phisher can\u2019t do much with it while you\u2019re <a href=\"https:\/\/en-gb.facebook.com\/help\/148233965247823\">protected with 2FA<\/a>. This isn&#8217;t a silver bullet though, as more and more phishers are also taking 2FA codes with them when they phish your details. <\/li>\n<li>Add <a href=\"https:\/\/www.facebook.com\/help\/162968940433354\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">login alerts<\/a> to your Facebook account. If someone does manage to get hold of your login credentials and access your account, you&#8217;ll get notified by Facebook as soon as this happens so you can grab your account back as soon as possible.<\/li>\n<\/ul>\n<p>Once your friend or family member regains access to their account, you can point them to these tips for keeping their own account locked down too. This way, you\u2019ll be that little bit more safer next time account harvesting phishers are on the prowl.<\/p>\n<p>Stay safe out there!<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/05\/look-what-i-found-here-phish-targets-facebook-users\/\">&#8220;Look what I found here&#8221; phish targets Facebook users<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/05\/look-what-i-found-here-phish-targets-facebook-users\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Christopher Boyd| Date: Tue, 17 May 2022 10:54:33 +0000<\/strong><\/p>\n<p>A Facebook Messenger phish is asking would-be victims to &#8220;take a look&#8221;. But what lies in wait for eager clickers?<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/05\/look-what-i-found-here-phish-targets-facebook-users\/\">&#8220;Look what I found here&#8221; phish targets Facebook users<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[26161,11380,26162,3589,1702,13429,26163,18100,10511,3924,10574],"class_list":["post-19062","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-bad-link","tag-chat","tag-contacts","tag-facebook","tag-family","tag-friends","tag-look-what-i-found","tag-messenger","tag-phish","tag-phishing","tag-scams"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19062","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=19062"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19062\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=19062"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=19062"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=19062"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}