All the latest UK technology news, reviews and analysis

Second phishing attack targets Facebook users

by Dave Neal

More from this author

29 Oct 2009

Be the first to comment

  • Tweet this
Facebook
Facebook users are under a concerted attack from cyber criminals

Facebook users are facing yet another malware attack this week, after security experts warned of a new phishing scam with a nasty payload.

Email hosting provider AppRiver said that the Zbot, or Zeus, botnet is delivering 30,000 messages a minute, and warned users to take extra care with unsolicited emails.

"We have already seen about 1.65 million messages from this campaign. As we've come to expect from Zbot, the phishing email is well crafted and could easily trick the unsuspecting recipient into falling for its ruse," Fred Touchette, a senior security analyst at AppRiver, said in a blog post.

"The graphics are well done and all look like something you would see from Facebook. The email informs users that Facebook is updating their log-in system to 'make things more secure', and urges people to click on the update button in the email.

"This should be enough anyone needs to see, considering that Facebook, your bank or anyone else, doesn't need every one of their users' participation in order to update their product."

Clicking on the link leads to a genuine-looking Facebook login screen that asks for the user's password. Another screen then asks them to download an update tool, which is actually the Zeus Trojan that typically targets bank accounts.

"Stay away from these emails. Zeus or Zbot spares no effort in making their attacks appear to be genuine. It is very important to protect yourself by being vigilant," said Touchette.

"If you don't personally know the sender, I would avoid clicking any links in emails, especially when the term 'your account' appears anywhere in the email."

This is the second phishing attack on Facebook users in as many days, following the discovery yesterday of a widespread attempt to trick users into giving away password and login details.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

97%

1%

1%

0%

1%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Oracle HRMS/CRM consultant- Incentive compensation module

Our client, a leading IT services and consulting organization...

Midweight PHP Developer // LAMP // HTML // CSS //

Midweight PHP Developer // LAMP // HTML // CSS...

Senior Data Analyst

My client a leading global financial company is seeking...

QA Test Analyst – Selenium RC – Java – Bug Tracker – Agile

QA Test Analyst – Selenium RC – Java – Automation – Bug...

To send to more than one email address, simply separate each address with a comma.