For approximately 48 hours between June 24 and 27, scammers used Facebook spam messages to distribute malware that hijacked user accounts to perform actions such as liking and sharing unwanted content.
A security researcher from Russian security firm Kaspersky Lab discovered the campaign, which was spreading between Facebook accounts in the form of a spam message received from a friend who notified users by mentioning them in a comment.
Visiting the link would initiate the first phase of the two-tiered attack, during which a trojan to the user's computer.
During the second stage, this trojan would secretly download and install an extension to the user's Chrome browser, if it was on the infected system.
The Chrome extension would wait until the user tried to access Facebook again, asking them to authenticate again. At this point, the extension would grab the user's Facebook username and password and send them to the scammer's server.
The fraudster would then take advantage of these credentials and assign these accounts to like and share the desired content, while also spamming the infected account's friends to further spread the malware.
The scammer behind this campaign was likely selling Facebook Likes and shares via the botnet from infected devices.
Due to the trojan's source code, this malware was only effective when users viewed the spam messages from Windows.
The Russian security firm said the malware tried to protect itself by blacklisting the homepages of several security software vendors.
“Two aspects of this attack stand out. First, the malware was extremely efficient, reaching thousands of users in just 48 hours. Second, the response from consumers and the media was truly swift. Their reaction raised awareness of the campaign and led to immediate action and investigation by the affected providers,” said Ido Naor, Senior Security Researcher, Global Research and Analysis Team at Kaspersky Lab.
Facebook engineers were notified and implemented blocking techniques used to prevent the spread of malware. Google also removed the rogue extension from Chrome Web Store .
According to Kaspersky data, the campaign created the most victims in countries such as Brazil, Poland, Peru, Colombia, Mexico, Ecuador, Greece, Portugal, Tunisia, Venezuela, Germany and Israel.


