Follow Us

Hacked Facebook apps push fake antivirus software

Four Facebook applications were modified to deliver viruses

A number of Facebook applications have been hacked to download malicious fake antivirus, a security researcher has found.

While researching websites that host malicious software, Roger Thompson, chief research officer of software security company AVG, noticed something funny. A Russian website known for hosting malware was getting lots of referrals from Facebook.

On further investigation, Thompson found the referrals were coming from a Facebook application called "City Fire Department," a game where multiple players respond to emergency calls. The application had been modified to deliver an iFrame, which is a way to bring content from one website into another.

The iFrame serves up code that tries to exploit vulnerabilities in a PC's software. If it finds one -- a process that happens nearly instantly -- it then downloads a fake antivirus program called Antivirus Pro 2010. Thompson posted screenshots on AVG's blog.

Bogus antivirus programs have been around for a long time, but they've become an increasing nuisance this year as those who create them seemed to have stepped up their game. When installed on computers, the programs nag users to buy them. The applications, which can cost upwards of US$60, are generally useless against real security threats.

Thompson thought the people who wrote City Fire Department might be behind the scam. But the malicious code was actually hosted on Facebook, which led Thompson to theorise that the developers of City Fire Department inadvertently had their Facebook passwords obtained by a hacker, after which the application was modified.

The password credentials could have been compromised through a phishing scam, or a developer's PC could have been hacked. City Fire Department's developers acknowledged a problem on Facebook on Thursday.

"The application has been taken offline until we can resolve all issues," according to the post. "We understand the frustration some users are feeling, and we will update with a timeline as soon as we can. Obviously, we would rather have a properly functioning game running instead of a half-working game."

Facebook has been notified. The social-networking site: "certainly takes security seriously, and they respond very quickly but the stuff that comes out of left field is hard to defend against," Thompson said.

Three or four other applications had also been modified, Thompson said. Facebook can deactivate the applications until they are cleaned up. The situation also poses a danger to enterprises, who may allow their users access to Facebook through their firewall, thus opening a vector to deliver malware.

"The corporate firewall doesn't provide any security," Thompson said.

Facebook representatives could not be immediately reached for comment.






Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

State of software security report volume 4

If your business has anything worth protecting, be it money, intellectual property or a trusted...

Download Whitepaper

New threats demand innovative responses

Financial institutions in the UK remain susceptible to further systemic problems, as challenging...

Download Whitepaper

Delivering a competitive advantage through IT

IT organisations share a common mission; to optimise investments and streamline operations to...

Download Whitepaper

6 tips to mobilise your existing ERP

Enterprise mobile users throughout the global business community will number 1.19 billion by...

Download Whitepaper

Techworld UK - Technology - Business

Techworld Awards

Techworld Awards Winners 2011


Learn who the winners of this year's Techworld Awards are. Video footage coming soon...

Find out more
Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

Site Map

* *