• On BNET: Online porn struggles for profits
October 28, 2009 1:16 PM PDT

Bank Trojan botnet targets Facebook users

by Elinor Mills
  • Font size
  • Print
  • 22 comments

On the heels of one fake Facebook e-mail scam, a researcher warned on Wednesday of another such campaign in which users of the popular social network are being tricked into revealing their passwords and downloading a Trojan that steals financial data.

In the latest scam being blasted to e-mail in-boxes, a legitimate-looking Facebook notice asks people to provide information to help the social network update its log-in system, said Fred Touchette, a senior security analyst at AppRiver. When the user clicks the "update" button in the e-mail, they are directed to a fake Facebook log-in screen where their user name is filled in and they are prompted to provide their password.

This is a screen shot of the message in the body of the fake Facebook e-mail.

(Credit: AppRiver)

When they provider that information, victims are taken to a page that offers an "Update Tool," but that is actually the Zeus bank Trojan that is designed to steal financial and personal data, Touchette said.

Users of smart phones that have the Facebook app installed can also easily be duped because the phishing e-mail appears as an actual Facebook notification complete with Facebook icon, he said. The message is received in the e-mail in-box on the phone as well as under the Facebook notification section in the app itself, he added.

There are likely to be a lot of victims given how many e-mails the scammers are sending. AppRiver has captured about 6 million e-mails in its filters and noticed that the messages were coming in at a rate of 30,000 a minute at one point, according to Touchette. That's about 10 times the usual botnet e-mail message rate, he said.

More details are on the AppRiver blog.

On Tuesday, researchers reported that a different botnet, Bredolab, was distributing fake "Facebook Password Reset Confirmation" e-mails that included a Trojan. As of late Wednesday night, security provider Cloudmark said it had seen more than 730,000 of the Bredolab-related e-mails.

To protect against such phishing attacks, people should be extremely cautious about clicking on links in e-mails and they can mouse over the link to see if the domain is a legitimate domain, Touchette said.

Meanwhile, Facebook users should easily be tipped off that the latest scam is just that, a scam, he said. "Facebook doesn't need all of its users to update their accounts in order for them to make changes to their site," he added.

If there is any question about the legitimacy of the e-mail or the link, users should close the e-mail and go directly to the site to check for important notices to customers, he said.

This is the prompt Facebook users get as part of the latest phishing scam. Downloading the "update tool" installs a Trojan.

(Credit: AppRiver)

Originally posted at InSecurity Complex
Elinor Mills covers Internet security and privacy. She joined CNET News in 2005 after working as a foreign correspondent for Reuters in Portugal and writing for The Industry Standard, the IDG News Service, and the Associated Press. E-mail Elinor.
Recent posts from Security
Log in with your face
See what's under McAfee's new interface
26 Windows, Office holes patched in 13 bulletins
McAfee: Spammers exploiting more news stories
Microsoft, Google split over browser bug bounty
Verizon temporarily blocks some 4chan sites
Security software maker Vitamin D exits beta
China breaks up Black Hawk hacking ring
Add a Comment (Log in or register) (22 Comments)
  • prev
  • next
by kaiman75 October 28, 2009 2:01 PM PDT
Just more reason for me to not sign up for a Facebook account and do my banking the old-fashioned way - by mail!
Reply to this comment
by StayConfused October 30, 2009 2:36 PM PDT
Hmmmm. You don't use Facebook to do online banking
by MiamiWebDesigner January 11, 2010 7:18 PM PST
Cloudmark Authority: Boom for Big Brother, Bust as Spam Filter<br /><br />[ Source: ldrlongdistancerider[dot]com/02 ] Euphemistically packaged and sold to the American Sheeple as a "spam filter", Cloudmark Authority is actually the email censorship software of choice in Communist China: tinyurl[dot]com/yb3vhx7<br /><br />Here in the United States, that same censorship system is installed on the email servers of many of our largest telecoms, internet service providers (ISPs), social networks and web hosting companies, including Network Solutions: cloudmark[dot]com/en/serviceproviders/<br /><br />Shortly after Network Solutions implemented Cloudmark Authority in late 2009, we and other Network Solutions clients became victims of its sinister Big Brother capabilities: tinyurl[dot]com/Defy-Cloudmark-Authority<br /><br />Since that time, we've experienced a regular pattern (see below) by which legitimate political email communications have either been blocked from being sent via SMTP, or blocked from being received via webmail or POP, or we have been blocked from receiving replies to those emails, or all of the above. In some cases, after multiple complaints, we have been able to get those blocks lifted. But in some cases, blocks that were lifted were eventually reactivated, even after we were assured by Network Solutions that such a thing "would not happen".<br /><br />Ironically, the number of unsolicited commercial emails (U.C.E. or "spam") delivered to our inboxes by Network Solutions has increased rather than decreased since they installed Cloudmark Authority (see below). So although our 1984-ish experiences validate Cloudmark Authority as a great censorship tool for Big Brother, as a spam blocker, spam filter or weapon against "messaging abuse", it's a bust.
by WinNoMo October 28, 2009 2:17 PM PDT
Oh my. My Mac doesn't seem to have this feature. Must be because it is such a niche toy with low market share. I am tired of being left out of these great opportunities! Makes me really miss Windows..................
Reply to this comment
by Vegaman_Dan October 28, 2009 3:13 PM PDT
"Makes me really miss Windows.................." <br /> <br />Somehow I don't think anyone misses you though.
by Dalkorian October 29, 2009 10:40 AM PDT
Now now, this particular nasty is a trojan. True it's custom built for winblows, but the user has to install it first. No OS is proof against users installing programs, so I wouldn't recommend relying on OS X's improved security to keep you safe.<br /><br />Never install programs sent unsolicited by email.
by Squeedle October 28, 2009 3:02 PM PDT
@kaiman75: That's clearly the best way, 'cause nobody ever steals checks sent through the mail, and mail never gets lost, either.
Reply to this comment
by Dalkorian October 29, 2009 10:42 AM PDT
Funny you mention that, when I need to (snail) mail something I *NEVER* use the mailbox in front of my house. I go to the local post office and mail from there. Just because I'm paranoid doesn't mean the world isn't out to get me.<br /><br />;-)
by suzyq032951 October 30, 2009 11:23 AM PDT
Yeah right. Mail never gets lost or stolen. That is why when I do mail a check, I take it straight to the post office, never mail from my home mail box. With on line banking, I can check as many times as I want and if I find a problem, I take it straight to the bank. Don't have to wait till the next statement to see what is going on with my bank accounts.
by gertruded October 28, 2009 3:09 PM PDT
Again the writer fails to tell us that this is a Windows Trojan. Be safe, do not use Windows on line. Windows is a good operating system as long as you stay off line with it. Load another operating system such as Ubuntu to go on line with. You will not face this trojan.
Reply to this comment
by Vegaman_Dan October 28, 2009 3:13 PM PDT
Or simply not be stupid or gullible enough to respond so such emails that are blatant attempts to steal your information. <br /> <br />I'll go with the second option.
by zyxxy October 29, 2009 6:00 AM PDT
Exactly. "Oh yes, let me give permission to this random .exe file that someone has just handed me."<br />Dumb and dumber.
by Dalkorian October 29, 2009 10:47 AM PDT
You missed the dangerous part Gertruded - it's a trojan. The user had to install it. Name one operating system that is proof against the user installing programs. The fact that the user was tricked is how a trojan works, you think you're getting one thing but get something else entirely.<br /><br />Note that I don't disagree with the idea that the only remotely secure winblows box is the one that is disconnected from any and all networks.
by zyxxy October 29, 2009 6:03 AM PDT
Which is exactly why the users (my family, including me) on the home PC do not have admin privilege and do not know the admin password. So when UAC asks for the admin password, they always click 'no'.<br /><br />Okay, I know the admin password, but I never grant it from my user account.
Reply to this comment
by Dalkorian October 29, 2009 10:48 AM PDT
If you think that poorly implemented UAC fecalware is protecting you in any way, you are severely delusional and should be prevented from operating any computer.
by mailhacker October 29, 2009 11:07 PM PDT
@Dalkorian - Just because its annoying doesnt mean it doesnt work. Mac fanboys. lol.
by Garken October 29, 2009 11:01 AM PDT
To Dakorian. Why don't you pay your uncle Kevorkian a visit ? It will solve all your mental issues with MS Windows. It will also save you the cost of a Mac too.
Reply to this comment
by gggg sssss October 29, 2009 1:06 PM PDT
why does cnet blur the offending download site. Shame them publicly I say
Reply to this comment 1 person likes this comment
by suzyq032951 October 30, 2009 11:24 AM PDT
Bottom line is NEVER give out your personal information on line. Facebook already has it so why would they ask for it again. I would never fall for that line.
Reply to this comment
by MiamiWebDesigner October 31, 2009 9:00 PM PDT
Big Brother Has a Name, and that Name is CLOUDMARK:<br /><br />tinyurl[dot]com/Cloudmark
Reply to this comment
by Hanzl November 2, 2009 10:44 AM PST
Windows Xp and Vista are very safe OS's. <br />Proven. <br />But they have a different approach regarding user setup. <br />XP comes with standard adminaccount enabled where Unix clones force you to create a useraccount and assign rights. Windows gave the users to much freedom and that created the problem. <br />Next Windows is so far more widespread that attacks have more profit to focus on Windows then on other systems. <br />The user is the dangerzone, not the OS.
Reply to this comment
by MiamiWebDesigner November 7, 2009 4:15 AM PST
Big Brother Has a Name, and that Name is CLOUDMARK: This 1984-ish content-based "spam signature" filter gives Network Solutions and other web hosts and ISPs complete control over what emails YOU are allowed to send or receive. They can define whatever they choose to be a "spam signature", including the name of a cause they don't support, or the business telephone numbers of people who do. Here is how I know: tinyurl[dot]com/Cloudmark
Reply to this comment
(22 Comments)
  • prev
  • next
advertisement

Google's social side aims for some Buzz

Facebook and Twitter are the darlings of the social-media world, not Google--which hopes to change that with Buzz, betting it can organize your online social life.

Watching the birth of a gaming start-up

Stewart Butterfield and his friends are back at it with a new company. CNET's Daniel Terdiman was given exclusive, behind-the-scenes access as they built it from scratch.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right