HomeSecurityESET check the address bar before entering Facebook

ESET check the address bar before entering Facebook

Security software developer ESET dissects an attack that stole the login credentials of thousands of Facebook members and comes up with an extremely useful recommendation for preventing the next “hit.” Making sure you’re “logged in” on Facebook will protect not only yourself but also your friends.

click to enlarge

fake facebook login

A new social fraud trojan has been able to steal login details from more than 16,000 Facebook accounts since late 2011, ESET has discovered. The malware's primary goal was to steal personal Facebook login details and, if the user was playing Texas HoldEm Poker, to link the data to user statistics for the popular and legal game from Zynga Inc., which has more than 35 million active users. According to ESET's detection statistics, the malware spread almost exclusively in Israel.

ESET began investigating the Trojan in early 2012, however, users of ESET security solutions were protected as early as December 2011, thanks to proactive detection of this threat. Also, as detection statistics indicated that the threat was only spreading in Israel, ESET had informed the Israeli CERT (Computer Emergency Response Team) and police authorities since early 2012. Now that the investigations are complete, the threat has been neutralized, and ESET is able to reveal information about the anatomy of the attack.

The attack relied on the use of malware to obtain the user's Facebook login details, their poker game score, as well as information stored in Facebook settings regarding the number of credit cards and the ability to increase credit in Texas HoldEm Poker, since the game had a feature that allowed users to replenish the chip value with real money by entering their credit card or PayPal account details.

To intercept the login credentials, the attack used an "army" of 800 computers, all of which were infected and controlled by the attacker, executing commands from the C&C (Command&Control) server.

The infected computers were instructed to log into the user's Facebook accounts and obtain their Texas HoldEm scores, as well as credit card information.

  • If the user did not have a credit card or had a low credit score, the infected computer was instructed to infect the victim's Facebook profile with a link leading to a phishing website, which directly or indirectly lured the user's friends to visit a website that resembled the Facebook homepage. If they entered their login details on that page, they were also infected.

ESET estimates that this attack gained access to the login details of 16,194 accounts, but points out that any Facebook application could be infected in this way, not just Texas HoldEm Poker.

  • “A good security solution is not enough to protect against attacks based on social fraud methods, we also need to be vigilant about such tricks ourselves,” points out Róbert Lipovský, Security Intelligence Team Lead at ESET, adding, “The user could recognize the fake Facebook page if they checked the site URL.”

The number of threats appearing on Facebook is growing rapidly. For this reason, ESET has released a new free security application, ESET Social Media Scanner, which can detect links with malicious and phishing content on a user's profile and the timeline of their friends on Facebook.

in

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS