Facebook Bug Security IT

Fake Facebook Emails Deliver Malware Masquerading As Audio Message 47

An anonymous reader writes: A new spam campaign is targeting Facebook users. It uses the same approach as the recent one aimed at WhatsApp users, and Comodo researchers believe that the authors of both campaigns are likely the same. The fake emails are made to look like an official communication from the popular social network, and their goal is to make the victims believe they have received a voice message. The attachment that the recipients are urged to download and open contains a malicious executable — a variant of the Nivdort information-stealing Trojan.
  • by 110010001000 ( 697113 ) on Thursday January 21, 2016 @03:38PM (#51346245) Homepage Journal
    I got that message. I figured what is the harm in opening an executable I received in an attachment. After all, this is 1992! Modern times!
    • I got that message. I figured what is the harm in opening an executable I received in an attachment. After all, this is 1992! Modern times!

      Evolution has selected Facebook users for extinction.

  • "Facebook users" (Score:2, Insightful)

    by Anonymous Coward

    I have no sympathy for anyone who uses Facebook and gets pwn3d by this shit.

    • by mccrew ( 62494 )

      I see that you have conveniently jumped straight to victim blaming rather than owning up to the bigger failing, which is why ordinary users should even have to worry about becoming owned by benign-looking attachments.

      Especially for tech creators like so many of us here, this seems applicable: "When you point a finger at someone else, remember that there are three other fingers pointing back at yourself."

      • The reality is that with choice comes a certain amount of responsibility. a woman should be able to wear a skimpy outfit and walk down dark alley's at night safe, a rich person should be able to have hundred dollar bills hanging out his pocket without fear of being mugged. The reality is that if you want the freedom to do that it comes with certain risks that society (or computer programmers) can't fully mitigate without you giving up some freedoms.
  • by Hognoxious ( 631665 ) on Thursday January 21, 2016 @04:00PM (#51346399) Homepage Journal

    How do real Facebook emails deliver it?

  • by martinux ( 1742570 ) on Thursday January 21, 2016 @04:00PM (#51346405)

    Much of the spam I see is Paypal and Facebook. Shouldn't spam filters be image matching logos or looking for company names in an email and verifying the email came from a domain associated with that company?

    • from the microsoft account team and a link to update my account information on some domain registered out of india that has been revoked... my spam filter caught it along with some similar ebay ones.

    • by Krojack ( 575051 )

      I just checked's SPF. They are set to SoftFail. I feel like they should have that set to HardFail. SPF isn't 100% perfect but it does help.

  • by bloodhawk ( 813939 ) on Thursday January 21, 2016 @04:27PM (#51346561)
    Sooo why is this an article here? seriously this has been a common attack method for over a decade.
  • by Anonymous Coward
    Literally nothing good comes from Facebook, why are you still using it?

    Oh, but how am I going to keep in touch with my 573,674 friends?

    LOL, you have FIVE friends, the rest are Facebook 'bots.

    I have Friends and Family I need to keep in touch with, they're important to me!

    If they're so goddamn important, why can't you pick up a phone once a week and, I dunno, actually TALK to them? Or how about something SO RADICAL as actually seeing people in person?

    I use this to represent my business

    LOL nobody cares, get a fuckign webpage like everyone else, loser, you just have NO FRIENDS and are lonely. Try OKCupid or something.

    You people are wasting time and energy and accomplishing NOTHING on F

  • "A new spam campaign is targeting Facebook users"

    Shouldn't that be spam campaign is targeting Microsoft Windows?

