Aug19 |
8:36 pm (UTC-7) | by
Jonathan Leopando (Technical Communications) |
It would be easy to think that once someone has logged in successfully to Facebook—and not a phishing site—that the security threat is largely gone. However, that’s not quite the case, as we’ve seen before.
Earlier this week, however, Trend Micro researcher Rik Ferguson found at least two—if not more—malicious applications on Facebook. (These were the Posts and Stream applications.) They were used for a phishing attack that sent users to a known phishing domain, with a page claiming that users need to enter their login credentials to use the application. The messages appear as notifications in a target user’s legitimate Facebook profile, as shown below. The links to the malicious site are highlighted:

Figure 1. Facebook notifications page
After entering the credentials, users would then be redirected to Facebook itself. (The posts detailing these findings can be found at the Counter Measures blog; the initial report is here and a follow-up was posted here.)
While Trend Micro has informed Facebook of these findings, users should still exercise caution when entering login credentials. They should be doubly sure that these are being entered into legitimate sites, and not carefully crafted phishing sites. The particular site involved in this phishing attack is already blocked by the Smart Protection Network.
Image credits: thanks to Rik Ferguson, Countermeasures blog.
Share this article |
|
19 Responses to “Facebook Applications Used For Phishing”
Trackbacks
- Twitter Trackbacks for Facebook Applications Used For Phishing [trendmicro.com] on Topsy.com
- TrendMicro (TrendMicro)
- _third (third marquez)
- kevinleb (Kevin Le Bouthillier)
- braciolanet (braciolanet)
- iia_security (Terry Walls)
- natecochrane (Nate Cochrane)
- GarlikCommunity (Garlik)
- Did you realize some Facebook apps are being used to steal your data? | HKNetLife - Blogging for Life
- Lurad på Facebook | jobbdator.se
- insecure » Facebook Applications Used For Phishing
- Sunday Roundup: Top Web Stories this Past Week III | WebDoctus
- Facebook looks for trust while scammers target their users — Groupings
- FaraVirusi.com » Aplicatii infectate pe Facebook
- Aplikasi Pencuri Data Facebook « Jaya saja…
- crolate (Cristián Olate)
- FaceBook Malicious Apps
- iGraphiX Blog | FaceBook Malicious Apps




August 20th, 2009 at 1:16 am
There has been an outbreak of viruses on facebook with all my friend with a virus called “Personal Anti-virus” or PAV. I had to clean my computer and my latop and my neighbor had the same infection. You guys should find out more on this infection and fix it please. Thank you your faithful customer