Security Affairs
Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback|Australian Police Charge Two Over TeamPCP Credential Theft|Meta to Pay Up to $18B Over Teen Social Media Use|CISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do|OpenAI banned Russian ChatGPT accounts backing covert influence operation|CISA Red Team Fully Compromised Two Critical Infrastructure Orgs|FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure|U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog|88 ID Verification Breaches Show the Cost of Collecting Identity Data|WhatsApp Adds Stronger Security as Passkeys Hit 1 Billion|Operation Jackal: 58 Arrests Expose the Money Laundering Machine Behind Global Scams|Norway ’s Digital Government Infrastructure Hit by a new DDoS Attack|Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback|Australian Police Charge Two Over TeamPCP Credential Theft|Meta to Pay Up to $18B Over Teen Social Media Use|CISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do|OpenAI banned Russian ChatGPT accounts backing covert influence operation|CISA Red Team Fully Compromised Two Critical Infrastructure Orgs|FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure|U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog|88 ID Verification Breaches Show the Cost of Collecting Identity Data|WhatsApp Adds Stronger Security as Passkeys Hit 1 Billion|Operation Jackal: 58 Arrests Expose the Money Laundering Machine Behind Global Scams|Norway ’s Digital Government Infrastructure Hit by a new DDoS Attack|
Advertisement

Ad Placeholder

Full Width × 90

Malware

A singular Facebook Trojan has already infected nearly 110,000 Facebook users

Security researcher is investigating in a new strain of Facebook Trojan that in just two days has already infected 1110,000 Facebook users. Social networks represent a privileged attack vector for malware-based attacks, a recent investigation conducted by by the security researcher Mohammad Faghani revealed the existence of a Trojan is circulating among Facebook users. According to the researcher, […]

A singular Facebook Trojan has already infected nearly 110,000 Facebook users

Security researcher is investigating in a new strain of Facebook Trojan that in just two days has already infected 1110,000 Facebook users.

Social networks represent a privileged attack vector for malware-based attacks, a recent investigation conducted by by the security researcher Mohammad Faghani revealed the existence of a Trojan is circulating among Facebook users. According to the researcher, the Trojan has already infected nearly 110,000 Facebook users in two days by spreading itself through malicious link.

Faghani explained that the Facebook Trojan spreads itself by posting links to a pornographic video from the account of unaware victims that have been previously infected.

The trojan tags the infected user’s friends in an enticing post. When users open the post, the user will see a preview of a porn video which eventually stops and asks for downloading a (fake) flash player to continue the preview, unfortunately the bogus application is the downloader of the Facebook Trojan.

facebook trojan 2

Faghani is still investigating on this Facebook Trojan and will provide further details via Full Disclosure in the next weeks.

The MD5 of the executable file (fake flash player): cdcc132fad2e819e7ab94e5e564e8968

The SHA1 of the executable file (fake flash player): b836facdde6c866db5ad3f582c86a7f99db09784

The fake flash file drops the following executables as it runs: chromium.exe,

  • chromium.exe
  • wget.exearsiv.exe,
  • arsiv.exe
  • verclsid.exe.

Pierluigi Paganini

(Security Affairs – Facebook Trojan, social network)