According to researchers, Facebook has been used by hackersas platform for Remote Access Trojans (RATs) since 2014.
Research by Check Point showed that this particular “large-scale” hacking campaign is related to political issues in Libya.
The campaign's goal was to spread RATs, most notably Houdini, Remcos, and SpyNote. According to researchers, the victims were mainly from Libya, Europe, the US , and China. It is estimated that tens of thousands of systems have been affected.
The hacker behind the campaign used the political unrest in Libya to their advantage. The hacker managed a Facebook page that supposedly belonged to the commander of the Libyan National Army, Khalifa Haftar, and through it, spread the malware .
The page, created in April 2019, was very persuasive, attracting over 11,000 Haftar followers. The postson the page were usually political and contained links to reports and material that were supposedly leaked and related to Libyan issues. In reality, if someone opened the links, they were directed to malicious content.

Opening the links led to the download of malicious VBE and WSF files for Windows computers and APK files with malware for the Android operating system . Executing the malicious files, in turn, led to the installation of a Trojan.
The malware was hosted on public services, such as Google Drive, Box, and Dropbox.
After the discovery of this page, many other pages, groups, and accounts both on and off Facebook, which were also used to distribute malware.
On Facebook, there were over 30 pages, which have shared around 40 malicious links, since 2014. In fact, one of them has affected over 100,000 users.
Researchers believe that the attacker may have also taken control of some popular, legitimate pages and is using them to his advantage.
To avoid arousing suspicion, the hacker may also publish legitimate content related to Libyan news. Among the legitimate content will be links that lead to fake applications and malicious services.
Researchers tracked the attacker through a command-and-control server that hosted and distributed malicious payloads, which led them to “Dexter Ly,” a Facebook account that the team says belongs to the hacker.
Dexter Ly appears to have participated in other attacks aimed at stealing confidential information about Libya.
“Although the attacker does not support a political party or any of the opposing sides in Libya, his actions appear to be motivated by political events,” the researchers said. “This may indicate that the attacker is targeting specific individuals.”.
The researchers informed Facebook of their findings, and the platform removed all relevant pages and accounts.
A Facebook spokesperson said:
“These pages and accounts violated our policies, so we removed them after Check Point researchers reported them. We work to keep malicious activity off Facebook and encourage people to be vigilant and not click on suspicious links.”.
