{"id":138352,"date":"2019-07-02T15:15:04","date_gmt":"2019-07-02T12:15:04","guid":{"rendered":"https:\/\/ww-vb.mine.nu\/w108\/facebook-removes-accounts-used-to-distribute-malware-since-2014\/"},"modified":"2019-07-02T15:15:04","modified_gmt":"2019-07-02T12:15:04","slug":"facebook-removes-accounts-used-to-distribute-malware-since-2014","status":"publish","type":"post","link":"https:\/\/hameed.nwar.uk\/sa\/facebook-removes-accounts-used-to-distribute-malware-since-2014\/","title":{"rendered":"Facebook removes accounts used to distribute malware since 2014"},"content":{"rendered":"<p> [ad_1]<br \/>\n<\/p>\n<div>\n<p>Facebook has shut down more than 30 accounts that were found to be spreading <a href=\"https:\/\/en.wikipedia.org\/wiki\/Remote_access_trojan\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Remote Access Trojans<\/a> (RATs) through malicious links that claimed to inform users about the ongoing political crisis in Libya.<\/p>\n<p>Dubbed \u2018Operation Tripoli,\u2019 the large-scale campaign \u2014 <a href=\"https:\/\/research.checkpoint.com\/operation-tripoli\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">uncovered by cybersecurity vendor Check Point Research<\/a> \u2014 found that these pages have been a malware distribution point at least since 2014, potentially infecting thousands of victims.<\/p>\n<p>According to researchers, the accounts \u2014 some with over 100,000 followers \u2014 lured unsuspecting victims into \u201cclicking links and downloading files that are supposed to inform about the latest airstrike in the country, or the capturing of terrorists, but instead contain[ed] malware.\u201d<\/p>\n<p>The incident serves as a reminder how social media platforms can be abused to launch malware attacks, even as companies are investing in a variety of automated and manual systems to keep malicious activities at bay.<\/p>\n<h3>What was the Campaign?<\/h3>\n<p>Researchers said they began investigating the campaign after spotting a Facebook page impersonating the commander of Libya\u2019s National Army, Khalifa Haftar, who is also a prominent Libyan-American political figure in the country.<\/p>\n<figure class=\"post-image post-mediaBleed aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1226247 size-featured_img lazy\" src=\"data:image\/gif;base64,R0lGODlhAQABAIAAAAAAAP\/\/\/yH5BAEAAAAALAAAAAABAAEAAAIBRAA7\" alt=\"\" width=\"796\" height=\"302\" sizes=\"auto, (max-width: 796px) 100vw, 796px\" data-src=\"https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/07\/facebook-pages-796x302.png\" data-lazy=\"true\" data-srcset=\"https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/07\/facebook-pages-796x302.png 796w, https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/07\/facebook-pages-280x106.png 280w, https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/07\/facebook-pages-540x205.png 540w, https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/07\/facebook-pages-270x102.png 270w, https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/07\/facebook-pages.png 1257w\"\/><figcaption>Credit: <a href=\"https:\/\/research.checkpoint.com\/operation-tripoli\/\" target=\"_blank\" rel=\"noopener noreferrer\">Check Point Research<\/a><\/figcaption><figcaption><a href=\"#\" data-url=\"https:\/\/twitter.com\/intent\/tweet?url=https%3A%2F%2Fthenextweb.com%2Fsecurity%2F2019%2F07%2F02%2Ffacebook-removes-accounts-used-to-distribute-malware-since-2014%2F&amp;via=thenextweb&amp;related=thenextweb&amp;text=Check out this picture on: The five most popular Facebook pages that were used in this attack\" data-title=\"Share The five most popular Facebook pages that were used in this attack on Twitter\" data-width=\"685\" data-height=\"500\" class=\"post-image-share popitup\" title=\"Share The five most popular Facebook pages that were used in this attack on Twitter\"><i class=\"icon icon--inline icon--twitter--dark\"\/><\/a>The five most popular Facebook pages that were used in this attack<\/figcaption><\/figure>\n<p>The Facebook page \u2014 created in April 2019 with over 11,000 followers \u2014 shared posts with links disguised as leaks from Libya\u2019s intelligence units.<\/p>\n<p>These leaks were purported to \u201ccontain documents exposing countries such as Qatar or Turkey conspiring against Libya, or photos of a captured pilot that tried to bomb the capital city of Tripoli.\u201d\u00a0Some URLs even urged users to download mobile apps that were meant for citizens interested in joining the Libyan armed forces.<\/p>\n<p>But in reality, these URLs attempted to download malicious scripts and rogue Android apps that were\u00a0variants of open source remote-administration tools like Houdini, Remcos, and SpyNote which grant the attacker remote access to the devices to stage various attacks.<\/p>\n<p>In a further attempt to mask their true intent, the URLs were concealed using URL shortening services like bit.ly and goo.gl. Secondly, the malicious scripts themselves were found to be stored in file hosting services such as Google Drive, Dropbox, and Box.<\/p>\n<figure class=\"post-image post-mediaBleed aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1226246 size-full lazy\" src=\"data:image\/gif;base64,R0lGODlhAQABAIAAAAAAAP\/\/\/yH5BAEAAAAALAAAAAABAAEAAAIBRAA7\" alt=\"\" width=\"643\" height=\"290\" sizes=\"auto, (max-width: 643px) 100vw, 643px\" data-src=\"https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/07\/malware-drive-url.png\" data-lazy=\"true\" data-srcset=\"https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/07\/malware-drive-url.png 643w, https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/07\/malware-drive-url-280x126.png 280w, https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/07\/malware-drive-url-540x244.png 540w, https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/07\/malware-drive-url-270x122.png 270w\"\/><figcaption>Credit: <a href=\"https:\/\/research.checkpoint.com\/operation-tripoli\/\" target=\"_blank\" rel=\"noopener noreferrer\">Check Point Research<\/a><\/figcaption><figcaption><a href=\"#\" data-url=\"https:\/\/twitter.com\/intent\/tweet?url=https%3A%2F%2Fthenextweb.com%2Fsecurity%2F2019%2F07%2F02%2Ffacebook-removes-accounts-used-to-distribute-malware-since-2014%2F&amp;via=thenextweb&amp;related=thenextweb&amp;text=Check out this picture on: A link to Google Drive that actually hosts a malicious Visual Basic script\" data-title=\"Share A link to Google Drive that actually hosts a malicious Visual Basic script on Twitter\" data-width=\"685\" data-height=\"500\" class=\"post-image-share popitup\" title=\"Share A link to Google Drive that actually hosts a malicious Visual Basic script on Twitter\"><i class=\"icon icon--inline icon--twitter--dark\"\/><\/a>A link to Google Drive that actually hosts a malicious Visual Basic script<\/figcaption><\/figure>\n<p>But they also found instances where the attacker managed to host malicious files on legitimate websites, including <a href=\"https:\/\/www.libyana.ly\/Default.aspx\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Libyana<\/a>, one of the largest mobile operators in Libya.<\/p>\n<p>\u201cAlthough the set of tools which the attacker utilized is not advanced nor impressive per se, the use of tailored content, legitimate websites and highly active pages with many followers made it much easier to potentially infect thousands of victims,\u201d Check Point researchers noted.<\/p>\n<p>The Facebook posts were found to be riddled with \u201cmany misspelled words, missing letters, and repeated typos in Arabic.\u201d The spelling mistakes were a vital clue in confirming that the content was generated by an Arabic speaker, as they were unlikely to be introduced by online translation engines.<\/p>\n<p>A lookup of some combinations of the incorrect phrasing led the researchers to a network of Facebook pages that contained the same unique mistakes, proving that they were all operated by the same threat actor.<\/p>\n<h3>Who is the attacker?<\/h3>\n<p>The malicious script files shared by the original Facebook page were all traced to the same command-and-control (C&amp;C) server with the domain name: drpc.duckdns[.]org.<\/p>\n<p>A C&amp;C server is typically a computer controlled by a cybercriminal which is used to issue commands to systems compromised by malware and receive stolen data from a target network.<\/p>\n<p>They also established that the domain resolved to an IP address that was associated with another website: libya-10[.]com[.]ly, which coincidentally was also used as a C&amp;C server to distribute malicious files back in 2017.<\/p>\n<p>Through a subsequent WHOIS domain lookup, the researchers ascertained that someone under the alias \u201cDexter Ly\u201d had registered both the domains using the email address drpc1070@gmail.com.<\/p>\n<p>The alias led the researchers to yet another Facebook account, which was found to repeat the same typos discovered in the earlier pages. A closer inspection of the account\u2019s Facebook habits also revealed that the attacker was able to get their hands on sensitive information belonging to government officials.<\/p>\n<h3>The Impact<\/h3>\n<p>The use of URL shortening services to generate the links allowed Check Point researchers to determine how many times a given link had been clicked and from what geographic location.<\/p>\n<p>The analysis revealed that Facebook pages were the most common source of the links. Most of the clicks themselves came from Libya. But it was also confirmed that the campaign reached as far as\u00a0Europe, the US, and Canada. It\u2019s worth noting here that a click doesn\u2019t necessarily mean a successful infection.<\/p>\n<figure class=\"post-image post-mediaBleed aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"size-featured_img wp-image-1226249 lazy\" src=\"data:image\/gif;base64,R0lGODlhAQABAIAAAAAAAP\/\/\/yH5BAEAAAAALAAAAAABAAEAAAIBRAA7\" alt=\"\" width=\"796\" height=\"305\" sizes=\"auto, (max-width: 796px) 100vw, 796px\" data-src=\"https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/07\/malware-reach-796x305.png\" data-lazy=\"true\" data-srcset=\"https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/07\/malware-reach-796x305.png 796w, https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/07\/malware-reach-280x107.png 280w, https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/07\/malware-reach-540x207.png 540w, https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/07\/malware-reach-270x103.png 270w, https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/07\/malware-reach.png 1103w\"\/><figcaption>Credit: <a href=\"https:\/\/research.checkpoint.com\/operation-tripoli\/\" target=\"_blank\" rel=\"noopener noreferrer\">Check Point Research<\/a><\/figcaption><figcaption><a href=\"#\" data-url=\"https:\/\/twitter.com\/intent\/tweet?url=https%3A%2F%2Fthenextweb.com%2Fsecurity%2F2019%2F07%2F02%2Ffacebook-removes-accounts-used-to-distribute-malware-since-2014%2F&amp;via=thenextweb&amp;related=thenextweb&amp;text=Check out this picture on: One link was clicked approximately 6,500 times, 5,120 out of which came from Libya\" data-title=\"Share One link was clicked approximately 6,500 times, 5,120 out of which came from Libya on Twitter\" data-width=\"685\" data-height=\"500\" class=\"post-image-share popitup\" title=\"Share One link was clicked approximately 6,500 times, 5,120 out of which came from Libya on Twitter\"><i class=\"icon icon--inline icon--twitter--dark\"\/><\/a>One link was clicked approximately 6,500 times, 5,120 out of which came from Libya<\/figcaption><\/figure>\n<p>Facebook has since shut down the pages and accounts that were distributing the malware as part of the campaign after Check Point researchers privately reported their findings.<\/p>\n<p>But considering the ongoing conflict in Libya between the elected government backed by the United Nations and Haftar-led Libyan National Army, the attacker\u2019s decision to exploit the crisis to bait users into clicking the malicious URLs raises serious security concerns. It also highlights\u00a0how <a href=\"https:\/\/searchsecurity.techtarget.com\/definition\/social-engineering\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">social engineering attacks<\/a> are gaining sophistication.<\/p>\n<p>\u201cAlthough the attacker does not endorse a political party or any of the conflicting sides in Libya, their actions do seem to be motivated by political events,\u201d the researchers concluded.<\/p>\n<p>The chain of events indicate that the threat actor leveraged Facebook\u2019s reach, and that they were aware of what their targets were likely to click or download, thereby enabling them to spread the files using simple yet effective methods.<\/p>\n<\/p><\/div>\n<p><script async src=\"http:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><br \/>\n<br \/>[ad_2]<br \/>\n<br \/><a href=\"https:\/\/thenextweb.com\/security\/2019\/07\/02\/facebook-removes-accounts-used-to-distribute-malware-since-2014\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[ad_1] Facebook has shut down more than 30 accounts that were found to be spreading Remote Access Trojans (RATs) through malicious links that claimed to inform users about the ongoing political crisis in Libya. Dubbed \u2018Operation Tripoli,\u2019 the large-scale campaign \u2014 uncovered by cybersecurity vendor Check Point Research \u2014 found that these pages have been &hellip;<\/p>\n","protected":false},"author":1,"featured_media":138353,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-138352","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tie-world"],"_links":{"self":[{"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/posts\/138352","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/comments?post=138352"}],"version-history":[{"count":0,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/posts\/138352\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/media\/138353"}],"wp:attachment":[{"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/media?parent=138352"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/categories?post=138352"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/tags?post=138352"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}