Trend Micro Facebook TrendLabs Twitter Malware Blog RSS Feed You Tube - Trend Micro
Search our blog:

  • Recent Posts

  • Calendar

    May 2012
    S M T W T F S
    « Apr    
     12345
    6789101112
    13141516171819
    20212223242526
    2728293031  
  • About Us
    Malware Blog > Facebook Scam Leverages Lady Gaga’s “Death,” Bypasses HTTPS

    We recently analyzed a Facebook spam that supposedly came from media organization, British Broadcasting Corporation (BBC). This reminded us of how cybercriminals used social networking site, LinkedIn, early last month.

    The attack starts with a wall post with the subject, BREAKING: Lady Gaga Found Dead in Hotel Room, and a link to the legitimate site, www.bbc.co.uk, as well as a description that says, “This is the most awful day in the US history.”

    This lured users with a video that was supposedly hosted on BBC’s site. Clicking the link in this wall post, however, actually redirected users to a malicious site.


    This site contains URLs, buttons, and images that replicate the legitimate BBC site. In reality, however, the page only contains a large image with the Play button being the only clickable element. Users who were curious enough to check out the video were prompted to complete a survey before they could play the video. While this is happening, their respective accounts were being set to Like the wall above-mentioned wall post.

    Clicking the You won! button leads to ad sites that allow attackers to earn money from every user visit.

    During our analysis, we also noted that this Facebook spam does not display a warning message for the site redirection, thus bypassing the site’s SSL/HTTPS feature even if it is enabled.

    Such Facebook attacks that use news items featuring celebrities, pop icons, and significant world events are something that we have seen before. Just recently, we noted a similar Facebook ruse, which used the recent demise of singer Amy Winehouse and required users to answer a survey and to disclose their mobile phone numbers.

    Users are advised to continuously be wary of such threats and avoid clicking links to such scams on Facebook. Trend Micro protects product users from this attack via the Smart Protection Network™ by blocking all related URLs.

    As cybercriminals persistently look for ways to use Facebook and other social networking sites for their malicious schemes, social media users can protect themselves by checking out our report, “Spam, Scams, and Other Social Media Threats.”

    Needless to say, Lady Gaga is still alive.





    Share this article
    Get the latest on malware protection from TrendLabs
    Email this story to a friend   Technorati   NewsVine   MySpace   Google   Live   del.icio.us   StumbleUpon




    17 Responses to “Facebook Scam Leverages Lady Gaga’s “Death,” Bypasses HTTPS”

    1. Tyler Willford Says:

      Damn they are getting clever aren’t they, thanks for the heads up.

    2. Technology Report Says:

      Very popular method that hackers use – something that people just can’t resist clicking on!!! Sneaky ******s!!! At least it’s been flagged up.

    3. Kim Says:

      I’m still waiting for Facebook to take action against these types of scams, they have been circulating on this social network way to long now. I bet these scams have resulted in people leaving Facebook.

      This is spam emails, on another level.

    4. wwe rumors Says:

      Facebook Should take serious actions against these kinds of Rumors and should ban those ips which are rapidly found in these kinds of activities.
      Hope for the better.

    5. Ben Says:

      Man, people will do anything to get people to click on things, I think some of those facebook scams are appalling. It’s especially terrible to make people think someone has died when they have not! Thanks for sharing this info though, I appreciate it!

    6. Rhombus Says:

      “This is the most awful day in the US history.”

      They even have a sense of humor as well. ;)

    Trackbacks

    1. TrendLabs (TrendLabs)
    2. ChadChoron (Chad Choron)
    3. Warning out vs ‘Lady Gaga is Dead’ Facebook scam – GMANews.TV
    4. Warning out vs ‘Lady Gaga is Dead’ Facebook scam | HollywoodDaily.us
    5. sps_it (SPS IT GmbH)
    6. 2020plus1 (Alan Potts)
    7. TrendMicro Malware Blog August 8, 2011
    8. Facebook Scam Leverages Lady Gaga Death, bypasses HTTPS | Malware Blog | Trend Micro
    9. Hurricane Irene Scam Hits Facebook | Malware Blog | Trend Micro
    10. Trend Micro Asia Pacific News Library - The Geography of Social Media Threats [INFOGRAPHIC]
    11. Una estafa basada en el huracán Irene se propaga por Facebook » blog.trendmicro.es


     

    © Copyright 2011 Trend Micro Inc. All rights reserved. Legal Notice