A new malicious campaign has appeared on Facebook. Its goal is to lure as many users as possible into clicking on a link that supposedly contains news. After the first click, the criminals use multiple redirects to websites serving the Nuclear Pack exploit kit.
It seems that scammers are becoming more sophisticated in their attacks, making the scam as profitable as possible. This time they figured that just one click wouldn't make them much money, so they started directing their victims to more URLs.
Symantec security researchers report that the trap is an article that supposedly reveals how a woman earns $8,000 a month without having to leave her home.
Users interested in discovering more details click on the link and end up on another page that starts redirecting to various malicious sites.
In some cases, some of these websites serve the Nuclear Pack exploit kit, which is known to leverage vulnerabilities in older versions of Java, Adobe Acrobat, and Adobe Reader.
However, in this example, the researchers report that the exploits used attempt to exploit security flaws in Microsoft's Internet Explorer (CVE-2013-2551) and Java (CVE-2012-1723).
"After successfully exploiting a vulnerability, the Nuclear Pack exploit kit drops Trojan.Ascesso.A. Trojan.Ascesso.A is known to send spam emails and download other files from a remote location," says Symantec's Ankit Singh.
Telemetry from Symantec systems shows that the regions most affected are North America and Europe.
A similar strategy based on multiple redirects to malicious pages specifically created to secure fraudsters money in one way or another has recently appeared on Facebook with a post purporting to contain news and videos from flight MH17.
Source: secnews.gr


