Malwarebytes security researchers have identified a new worm on Facebook, which spreads by exploiting the popular cloud services, Amazon Web Services and Box.
Social media is the main vehicle for attack, according to recent reports published by researchers that confirm that cybercriminals are exploiting these platforms for their illegal activities.
Facebook could of course not be an exception, and as it was found, the popular social network is being used to spread the dangerous worm, which belongs to the Kilim malware family, and can turn any computer into a "zombie", or in other words, a member of the botnet .
According to a report published by Malwarebytes, the attack chain begins with a tempting message on Facebook, promising users revealing photos of teenagers, of pornographic content.
The message includes an ow.ly link, which redirects victims to a URL, which in turn leads to an Amazon Web Services (AWS) page. The redirects don’t end there, however, as the Amazon Web Services (AWS) page actually takes victims to a malicious website (videomasars.healthcare), which is used by the scammers to determine which platform the users are using (desktop or mobile) in order to redirect them to different websites depending on the device they are using.
Mobile users are redirected to websites that generate revenue through affiliate marketing and contain various offers, while users using desktop computers are asked to download a file from the cloud service Box, which contains malware.
The file appears to contain a collection of videos (Videos_New.mp4_2942281629029.exe), but by scanning it with security software, it is possible to verify its malicious nature. The malicious file is a downloader for the Facebook worm, which comes in the form of a Chrome extension, and also includes some additional executables.
Researchers found that the worm also creates a shortcut for Chrome, which actually launches a malicious app in the browser, directly to the Facebook website.
“As previously mentioned, a fake Chrome extension is installed, but the story doesn’t end there. The malware also creates a Chrome shortcut that actually launches a malicious app in the browser, directly to the Facebook website,” Malwarebytes wrote in a blog post. “In this modified version of the browser, the attackers have full control, and can monitor all user activities, as well as restrict certain features.”.
For example, attackers disable the extensions page – which users can normally access by typing chrome://extentions/ – in an attempt to prevent users from disabling or removing the malicious extension.
The final stage of the attack involves sending malicious messages to all of the victims' friends, also promising access to pornographic content, with the aim of infecting more and more users and spreading the worm across the social network.

