• On CHOW: Can girls use the guys' bathroom?
August 19, 2009 2:45 PM PDT

Rogue Facebook apps steal log-in data, send spam

by Elinor Mills
  • Font size
  • Print
  • 9 comments

Security firm Trend Micro warned on Wednesday that a handful of rogue Facebook apps are stealing log-in credentials and spamming victims' friends.

So far, six malicious applications have been identified: "Stream," "Posts," "Your Photos," "Birthday Invitations," "Inbox (1)," "Inbox (2)" according to a blog post by Trend Micro researcher Rik Ferguson.

As of Wednesday afternoon, all of the apps were live except for "Stream," he said in an e-mail.

This screenshot shows evidence of the phishing scam on Facebook.

(Credit: Trend Micro)

The activity started earlier in the week with a Facebook notification Ferguson says he got from an app called "sex sex sex and more sex!!!," which has more than 287,000 fans. The notification said that someone had commented on one of his posts. That app doesn't appear to be malicious and may have been compromised somehow to begin the distribution of the spam, he said.

That first notification included hyperlinks that led to a phishing site on the "fucabook.com" domain, allegedly registered to someone in Armenia, he said. Once Ferguson gave up his credentials (for a Facebook account he uses for research purposes) he was directed to Facebook and to an application install screen for the app called "Posts."

He installed that app and immediately his friends were spammed with a bogus notification "Profile_name has sent you a message," with the hyperlink to the phishing site.

On Tuesday, the first couple of apps were sending notifications that hyperlinked to the fucabook phishing site but by Wednesday the destination had changed to a simple IP address rather than a domain name, he said. A JavaScript that pulls up Facebook bounces the browser around among any of the six rogue apps to get them widely installed and the cycle continues, he said.

All the apps look and act exactly the same and include ads.

"I am keeping Facebook informed of these developments as they arise and they are working hard to rectify the situation," Ferguson wrote on his blog.

A Facebook spokeswoman said the company was looking into the matter and would provide more comment later.

Ferguson recommends that Internet users always check the URL displayed in the browser address bar before entering any sensitive information on a site and hover the mouse over a hyperlink to see the URL. Facebook users should also review their privacy settings regularly and delete any applications they no longer use, he said.

Originally posted at InSecurity Complex
Elinor Mills covers Internet security and privacy. She joined CNET News in 2005 after working as a foreign correspondent for Reuters in Portugal and writing for The Industry Standard, the IDG News Service, and the Associated Press. E-mail Elinor.
Recent posts from Security
Log in with your face
See what's under McAfee's new interface
26 Windows, Office holes patched in 13 bulletins
McAfee: Spammers exploiting more news stories
Microsoft, Google split over browser bug bounty
Verizon temporarily blocks some 4chan sites
Security software maker Vitamin D exits beta
China breaks up Black Hawk hacking ring
Add a Comment (Log in or register) (9 Comments)
  • prev
  • next
by Pete Bardo August 19, 2009 3:05 PM PDT
I detest those Facebook apps, and not just the ones listed here. Please don't send me gifts or drinks or quizzes or any of that crap!
Reply to this comment
by cyberslick50 August 19, 2009 3:28 PM PDT
People should also be eagarly awaiting the Facebook application that spams text messages. Unfortunately these applications get verification to pull data from your profile, and if anybody out there has entered thier home address or cell phone number in an attempt to keep thier freinds up to speed, they are also potentially putting themselves at risk to these types of applications. Imagine an application that sends advertisements or bomb texts to somebody who made the mistake of sharing thier mobile number on a site they haphazardly accept friend and "application" requests at. Pandemonium! Do you think Facebook or the carriers will refund those charges? I think not. Be careful people. Take that recommendation to heart and CHECK the ACTUAL site you are submitting data to. Simplu hover over the link and check the bar at the bottom of your browser. Simple.
Reply to this comment
by gggg sssss August 19, 2009 4:46 PM PDT
bad on facebook to create aps that can do anything with data. Die facebook die
Reply to this comment
by kraterz August 20, 2009 2:07 AM PDT
Who has the time to waste on facebook apps? The less info they gather from you the better. People seem to have forgotten about privacy and how personal info can be misused, in the thrill of playing with new toys (apps).
Reply to this comment
by Internet-Lawyer August 20, 2009 3:59 AM PDT
The problem with Spam is not that it exists. SPAM is Legal. The problem is the collection methodologies used by the Spammers. As an <a href="http://www.web20lawyer.com">Internet Lawyer</a> I often work on bringing online direct marketers practices into legal compliance. Most assume that SPAM is illegal. In fact its a legal practice if done correctly.
Reply to this comment
by waxoval August 20, 2009 4:15 AM PDT
"Most assume that SPAM is illegal. In fact its a legal practice if done correctly."<br /><br />and that makes it ok then?
by gggg sssss August 20, 2009 5:59 AM PDT
well in the US at least, UCE IS illegal.
by santuccie August 20, 2009 6:04 PM PDT
Actually, "spam" is by definition unsolicited, be it through e-mail, forums, chat rooms, IM, VoIP, or otherwise. UCE is just one form of e-mail spam, usually involving an advertisement for a real company. Another type of spam is phishing; and yet another is a letter purporting to be from a long-lost friend, carrying a botnet Trojan with hopes of adding your machine to their network.<br /><br />@Internet-Lawyer: I won't assume you don't know what you're talking about, but even experts can overlook minor details. Commercial e-mail is legal if the recipient has done business with the sender and agrees to receive advertisements from them and/or their partners (whether or not they read the fine print), or if the recipient has joined an opt-in list. But unsolicited correspondence is indeed illegal, whether or not it bears a "CAN-SPAM" compliance statement or an "unsubscribe" link.
by wiindwalker October 2, 2009 11:37 AM PDT
I am done with facebook
Reply to this comment
(9 Comments)
  • prev
  • next
advertisement

Google's social side aims for some Buzz

Facebook and Twitter are the darlings of the social-media world, not Google--which hopes to change that with Buzz, betting it can organize your online social life.

Watching the birth of a gaming start-up

Stewart Butterfield and his friends are back at it with a new company. CNET's Daniel Terdiman was given exclusive, behind-the-scenes access as they built it from scratch.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right