No, it's not You in the Facebook Video... it's a Phishing Link

Stu Sjouwerman | Dec 21, 2020

Facebook Messenger Videos Phishing AttackScammers are using compromised Facebook accounts to circulate phishing attack to the hacked accounts’ friends, according to Paul Ducklin at Naked Security. The links are sent via Facebook Messenger, and appear to be a video with a blacked-out image and a caption that says “Is it you in the video?” Ducklin notes that these messages are much more effective when they come from a trusted account.

“From someone you didn’t know, a question like that would fall somewhere between bizarre and creepy, but from a friend, who wouldn’t want to take a look?” Ducklin says. “There is no video, of course – the black image links to a URL shortening service, which in turn redirects to a URL that pops up what looks like a Facebook login page.”

If a user enters their Facebook credentials on this phishing page, their own account will be hacked and their friends will then receive similar messages. Interestingly, the criminals in this case attempt to trick their victims twice by redirecting them to third-party scams after stealing their credentials.

“After entering your password, there’s a short delay, as you might expect when logging in to any online service, after which the crooks seem to pick from a range of other scams and redirect you to one of them randomly,” Ducklin says. “These didn’t look as though they were being run by the same criminals, so we’re assuming the message-spamming crooks were simply hoping to collect ‘affiliate fees’ from other criminals in the underground. These ‘second redirect’ scams varied from specious VPN offers to a range of those ‘free’ phone deals where all you need to do is pay a modest delivery fee (£1.95 in the variants we saw here), thus giving the crooks a believable excuse to collect your credit card details.”

New-school security awareness training can help your employees recognize scams and teach them not to let their curiosity get the better of them.

Naked Security has the full story

Topics: Phishing

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the human and AI workforce to make safer security decisions every day. Trusted by over 70,000 organizations worldwide, we help strengthen security culture and manage risk. Our comprehensive AI-driven platform includes awareness and compliance training, cloud email security, real-time coaching, crowdsourced anti-phishing, AI Defense Agents, agent security and more. As the only global security platform of its kind, KnowBe4 provides personalized content, tools, and techniques to keep the modern workforce safe from phishing, vishing, deepfakes, and emerging threats.

Get the latest insights, trends and security news. Subscribe to CyberheistNews.