<!DOCTYPE html>
<html class="client-nojs vector-feature-night-mode-disabled vector-feature-language-in-header-enabled vector-feature-language-in-main-page-header-disabled vector-feature-page-tools-pinned-disabled vector-feature-toc-pinned-clientpref-1 vector-feature-main-menu-pinned-disabled vector-feature-limited-width-clientpref-1 vector-feature-limited-width-content-enabled vector-feature-custom-font-size-clientpref-1 vector-feature-appearance-pinned-clientpref-1 vector-sticky-header-enabled" lang="en" dir="ltr"><head>
<meta charset="UTF-8">
<title>Facebook malware</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://en.wikipedia.org/wiki/Facebook_malware"> <link href="./mw/ext.cite.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.icons.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.search.codex.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/user.styles.css" rel="stylesheet" type="text/css">
<meta name="ResourceLoaderDynamicStyles" content="">
<link rel="stylesheet" type="text/css" href="./mw/site.styles.css">
<link rel="stylesheet" type="text/css" href="./mw/noscript.css">
<link rel="stylesheet" type="text/css" href="./footer.css">
<link rel="stylesheet" type="text/css" href="./vector-2022.css">
</head>
<body class="skin--responsive skin-vector skin-vector-search-vue mediawiki ltr sitedir-ltr mw-hide-empty-elt ns-0 ns-subject page-Facebook_malware rootpage-Facebook_malware skin-vector-2022 action-view">
<div class="mw-page-container">
<div class="mw-page-container-inner">
<div class="mw-content-container">
<main id="content" class="mw-body">
<header class="mw-body-header vector-page-titlebar">
<h1 id="firstHeading" class="firstHeading mw-first-heading">
<span id="openzim-page-title" class="mw-page-title-main"><span class="mw-page-title-main">Facebook malware</span></span>
</h1>
</header>
<a id="top"></a>
<div id="bodyContent" class="vector-body ve-init-mw-desktopArticleTarget-targetContainer" aria-labelledby="firstHeading" data-mw-ve-target-container="">
<div id="mw-content-text" class="mw-body-content mw-content-ltr" lang="en" dir="ltr"><div class="mw-content-ltr mw-parser-output" lang="en" dir="ltr">
<p>The <a href="Social_media_platform" class="mw-redirect" title="Social media platform">social media platform</a> and <a href="Social_networking_service" title="Social networking service">social networking service</a> <a href="Facebook" title="Facebook">Facebook</a> has been affected multiple times over its history by intentionally harmful software. Known as <a href="Malware" title="Malware">malware</a>, these pose particular challenges both to users of the platform as well as to the personnel of the <a href="Technology_company" title="Technology company">tech-company</a> itself. Fighting the entities that create these is a topic of ongoing <a href="Malware_analysis" title="Malware analysis">malware analysis</a>.
</p>
<meta property="mw:PageProp/toc">
<div class="mw-heading mw-heading2"><h2 id="Types_of_malware_and_notable_incidents">Types of malware and notable incidents</h2></div>
<p>Attacks known as <a href="Phishing" title="Phishing">phishing</a>, in which an attacker pretends to be some trustworthy entity in order to solicit private information, have increased exponentially in the <a href="2010s_(decade)" class="mw-redirect" title="2010s (decade)">2010s</a> and posed frustrating challenges. For Facebook in particular, tricks involving <a href="URLs" class="mw-redirect" title="URLs">URLs</a> are common; attackers will maliciously use a similar website such as <i>http://faceb0ok.com/</i> instead of the correct <i>http://facebook.com/</i>, for example. The 11th International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment (<a href="DIMVA" class="mw-redirect" title="DIMVA">DIMVA</a>), held in July 2014, issued a report condemning this as one of the "common tricks" that <a href="Mobile_computing" title="Mobile computing">mobile computing</a> users are especially vulnerable to.<sup id="cite_ref-Dietrich_1-0" class="reference"><a href="#cite_note-Dietrich-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup>
</p><p>In terms of applications, Facebook has also been visually copied by phishing attackers, who aim to confuse individuals into thinking that something else is the legitimate Facebook <a href="Login" title="Login">log-in screen</a>.<sup id="cite_ref-Dietrich_1-1" class="reference"><a href="#cite_note-Dietrich-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup>
</p><p>In 2013, a variant of the <a href="Dorkbot_(malware)" title="Dorkbot (malware)">"Dorkbot" malware</a> caused alarm after spreading through Facebook's internal chat service.<sup id="cite_ref-2" class="reference"><a href="#cite_note-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup> With suspected efforts by cybercriminals to harvest users' passwords affecting individuals from nations such as <a href="Germany" title="Germany">Germany</a>, <a href="India" title="India">India</a>, <a href="Portugal" title="Portugal">Portugal</a>, and the <a href="United_Kingdom" title="United Kingdom">United Kingdom</a>. The <a href="Antivirus" class="mw-redirect" title="Antivirus">antivirus</a> organization <a href="Bitdefender" title="Bitdefender">Bitdefender</a> discovered several thousand malicious links taking place in a twenty-four hour period, and contacted the Facebook administration about the problem. While the infection was contained, its unusual nature sparked interest given that the attackers exploited a flaw in the file-sharing site MediaFire to proliferate phony applications among victims' <a href="Friend_(Facebook)" class="mw-redirect" title="Friend (Facebook)">Facebook friends</a>.<sup id="cite_ref-3" class="reference"><a href="#cite_note-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup>
</p><p>The real <a href="Computer_worm" title="Computer worm">computer worm</a> "<a href="Koobface" title="Koobface">Koobface</a>", which surfaced in 2008 via messages sent through both Facebook and <a href="MySpace" class="mw-redirect" title="MySpace">MySpace</a>, later became subject to inflated, grandiose claims about its effects and spread to the point of being an <a href="Hoaxing" class="mw-redirect" title="Hoaxing">internet hoax</a>. Later commentary claimed a link between the malware and <a href="Facebook_message" class="mw-redirect" title="Facebook message">messages</a> about the <a href="Barack_Obama_administration" class="mw-redirect" title="Barack Obama administration">Barack Obama administration</a> that never actually existed. David Mikkelson of <a href="Snopes.com" class="mw-redirect" title="Snopes.com">Snopes.com</a> discussed the matter in a <a href="Fact-checking" title="Fact-checking">fact-checking</a> article.<sup id="cite_ref-4" class="reference"><a href="#cite_note-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup>
</p><p>On 26 July 2022, researchers at <a href="F-Secure" title="F-Secure">WithSecure</a> discovered a cybercriminal operation that was targeting digital marketing and human resources professionals in an effort to hijack Facebook Business accounts using data-stealing malware.They dubbed the campaign as 'Ducktail' and found evidence to suggest that a Vietnamese threat actor has been developing and distributing the malware with motives appeared to be purely financially driven.<sup id="cite_ref-5" class="reference"><a href="#cite_note-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Responses">Responses</h2></div>
<div class="mw-heading mw-heading3"><h3 id="Individual_efforts">Individual efforts</h3></div>
<p>In the same vein as actions by <a href="Google" title="Google">Google</a> and <a href="Microsoft" title="Microsoft">Microsoft</a>, the company's administration has been willing to hire "<a href="Grey_hat" title="Grey hat">grey hat</a>" hackers, who have acted legally ambiguously in the past, to assist them in various functions. Programmer and social activist <a href="George_Hotz" title="George Hotz">George Hotz</a> (also known by the <a href="Nickname" title="Nickname">nickname</a> "GeoHot") is an example.<sup id="cite_ref-Yin_6-0" class="reference"><a href="#cite_note-Yin-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-7" class="reference"><a href="#cite_note-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Bug_Bounty_Program">Bug Bounty Program</h3></div>
<p>On July 29, 2011, Facebook announced an effort called the "Bug Bounty Program" in which certain security researchers will be paid a minimum of <a href="United_States_Dollar" class="mw-redirect" title="United States Dollar">$</a>500 for reporting security holes on Facebook's website itself. The company's <a rel="nofollow" class="external text" href="https://web.archive.org/web/20111222084843/http://www.facebook.com/whitehat/">official page</a> for security researchers stated, "If you give us a reasonable time to respond to your report before making any information public and make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service during your research, we will not bring any lawsuit against you or ask law enforcement to investigate you."<sup id="cite_ref-8" class="reference"><a href="#cite_note-8"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup> The effort attracted notice from publications such as <i><a href="PC_Magazine" class="mw-redirect" title="PC Magazine">PC Magazine</a></i>, which noted that individuals must not just be the first to report the security glitch but must also find the problem native to Facebook (rather than an entity merely associated with it such as <a href="FarmVille" title="FarmVille">FarmVille</a>).<sup id="cite_ref-Yin_6-1" class="reference"><a href="#cite_note-Yin-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Targeting_of_specific_users">Targeting of specific users</h3></div>
<p>In late 2017, Facebook systematically disabled accounts operated by <a href="North_Korea" title="North Korea">North Koreans</a> in response to <a href="Government_of_North_Korea" title="Government of North Korea">that government's</a> use of state-sponsored malware attacks. <a href="Microsoft" title="Microsoft">Microsoft</a> did similar actions. The North Korean government had attracted widespread condemnation in the U.S. and elsewhere for its alleged proliferation of the <a href="WannaCry_ransomware_attack" title="WannaCry ransomware attack">"WannaCry" malware</a>. Said computer worm affected over 230,000 computers in over 150 countries throughout 2017.<sup id="cite_ref-9" class="reference"><a href="#cite_note-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="See_also">See also</h2></div>
<ul><li><a href="Facebook" title="Facebook">Facebook</a>
<ul><li><a href="Criticism_of_Facebook" title="Criticism of Facebook">Criticism of Facebook</a></li>
<li><a href="History_of_Facebook" title="History of Facebook">History of Facebook</a></li>
<li><a href="Issues_involving_social_networking_services" class="mw-redirect" title="Issues involving social networking services">Issues involving social networking services</a></li>
<li><a href="Privacy_concerns_of_Facebook" class="mw-redirect" title="Privacy concerns of Facebook">Privacy concerns of Facebook</a></li></ul></li>
<li><a href="Malware" title="Malware">Malware</a>
<ul><li><a href="Browser_hijacking" title="Browser hijacking">Browser hijacking</a></li>
<li><a href="Computer_worm" title="Computer worm">Computer worm</a></li>
<li><a href="Malware_analysis" title="Malware analysis">Malware analysis</a></li>
<li><a href="Mobile_malware" title="Mobile malware">Mobile malware</a></li>
<li><a href="Phishing" title="Phishing">Phishing</a></li>
<li><a href="Security_engineering" title="Security engineering">Security engineering</a></li></ul></li></ul>
<div class="mw-heading mw-heading2"><h2 id="References">References</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1239543626">
/* start https://en.wikipedia.org/ */
.mw-parser-output .reflist{margin-bottom:0.5em;list-style-type:decimal}@media screen{.mw-parser-output .reflist{font-size:90%}}.mw-parser-output .reflist .references{font-size:100%;margin-bottom:0;list-style-type:inherit}.mw-parser-output .reflist-columns-2{column-width:30em}.mw-parser-output .reflist-columns-3{column-width:25em}.mw-parser-output .reflist-columns{margin-top:0.3em}.mw-parser-output .reflist-columns ol{margin-top:0}.mw-parser-output .reflist-columns li{page-break-inside:avoid;break-inside:avoid-column}.mw-parser-output .reflist-upper-alpha{list-style-type:upper-alpha}.mw-parser-output .reflist-upper-roman{list-style-type:upper-roman}.mw-parser-output .reflist-lower-alpha{list-style-type:lower-alpha}.mw-parser-output .reflist-lower-greek{list-style-type:lower-greek}.mw-parser-output .reflist-lower-roman{list-style-type:lower-roman}
/* end https://en.wikipedia.org/ */
</style><div class="reflist">
<div class="mw-references-wrap"><ol class="references">
<li id="cite_note-Dietrich-1"><span class="mw-cite-backlink">^ <a href="#cite_ref-Dietrich_1-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-Dietrich_1-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><style data-mw-deduplicate="TemplateStyles:r1238218222">
/* start https://en.wikipedia.org/ */
.mw-parser-output cite.citation{font-style:inherit;word-wrap:break-word}.mw-parser-output .citation q{quotes:"\"""\"""'""'"}.mw-parser-output .citation:target{background-color:rgba(0,127,255,0.133)}.mw-parser-output .id-lock-free.id-lock-free a{background:url("./mw/Lock-green.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-limited.id-lock-limited a,.mw-parser-output .id-lock-registration.id-lock-registration a{background:url("./mw/Lock-gray-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-subscription.id-lock-subscription a{background:url("./mw/Lock-red-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .cs1-ws-icon a{background:url("./mw/Wikisource-logo.svg")right 0.1em center/12px no-repeat}body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-free a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-limited a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-registration a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-subscription a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .cs1-ws-icon a{background-size:contain;padding:0 1em 0 0}.mw-parser-output .cs1-code{color:inherit;background:inherit;border:none;padding:inherit}.mw-parser-output .cs1-hidden-error{display:none;color:var(--color-error,#d33)}.mw-parser-output .cs1-visible-error{color:var(--color-error,#d33)}.mw-parser-output .cs1-maint{display:none;color:#085;margin-left:0.3em}.mw-parser-output .cs1-kern-left{padding-left:0.2em}.mw-parser-output .cs1-kern-right{padding-right:0.2em}.mw-parser-output .citation .mw-selflink{font-weight:inherit}@media screen{.mw-parser-output .cs1-format{font-size:95%}html.skin-theme-clientpref-night .mw-parser-output .cs1-maint{color:#18911f}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .cs1-maint{color:#18911f}}
/* end https://en.wikipedia.org/ */
</style><cite id="CITEREFDietrich,_Sven2014" class="citation book cs1">Dietrich, Sven, ed. (2014). <a rel="nofollow" class="external text" href="https://books.google.com/books?id=2dokBAAAQBAJ"><i>Detection of Intrusions and Malware, and Vulnerability Assessment: 11th International Conference, DIMVA 2014, Egham, UK, July 10-11, 2014, Proceedings</i></a>. Springer. pp. 79, <span class="nowrap">84–</span>85. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a> <bdi>9783319085098</bdi>.</cite></span>
</li>
<li id="cite_note-2"><span class="mw-cite-backlink"><b><a href="#cite_ref-2">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.webtitan.com/blog/dorkbot-malware-on-facebook-chat-compromises-web-security/">"Dorkbot Malware Spotted on Facebook Chat"</a>. <i>WebTitan DNS Filter</i>. 2013-05-14<span class="reference-accessdate">. Retrieved <span class="nowrap">2021-11-21</span></span>.</cite></span>
</li>
<li id="cite_note-3"><span class="mw-cite-backlink"><b><a href="#cite_ref-3">^</a></b></span> <span class="reference-text"><cite id="CITEREFGonsalves2013" class="citation news cs1">Gonsalves, Antone (May 14, 2013). <a rel="nofollow" class="external text" href="https://www.csoonline.com/article/2133458/malware-cybercrime/facebook-attacked-with-credential-harvesting-malware.html">"Facebook attacked with credential-harvesting malware"</a>. <a href="CSOonline.com" class="mw-redirect" title="CSOonline.com">CSOonline.com</a><span class="reference-accessdate">. Retrieved <span class="nowrap">January 10,</span> 2018</span>.</cite></span>
</li>
<li id="cite_note-4"><span class="mw-cite-backlink"><b><a href="#cite_ref-4">^</a></b></span> <span class="reference-text"><cite id="CITEREFMikkelson2008" class="citation web cs1">Mikkelson, David (14 July 2008). <a rel="nofollow" class="external text" href="https://www.snopes.com/computer/virus/koobface.asp">"'Koobface' Virus Warning"</a>. <i><a href="Snopes.com" class="mw-redirect" title="Snopes.com">Snopes.com</a></i><span class="reference-accessdate">. Retrieved <span class="nowrap">January 10,</span> 2018</span>.</cite></span>
</li>
<li id="cite_note-5"><span class="mw-cite-backlink"><b><a href="#cite_ref-5">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://techcrunch.com/2022/07/26/ducktail-facebook-business-hijack-accounts/">"A newly discovered malware hijacks Facebook Business accounts"</a>. <i>Tech Crunch</i>. 26 July 2022<span class="reference-accessdate">. Retrieved <span class="nowrap">26 July</span> 2022</span>.</cite></span>
</li>
<li id="cite_note-Yin-6"><span class="mw-cite-backlink">^ <a href="#cite_ref-Yin_6-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-Yin_6-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFYin2011" class="citation magazine cs1">Yin, Sara (August 2, 2011). <a rel="nofollow" class="external text" href="https://www.pcmag.com/article2/0,2817,2389460,00.asp">"Facebook Offers $500 Bounty for Reporting Bugs: Why So Cheap"</a>. <i><a href="PC_Magazine" class="mw-redirect" title="PC Magazine">PC Magazine</a></i><span class="reference-accessdate">. Retrieved <span class="nowrap">January 10,</span> 2018</span>.</cite></span>
</li>
<li id="cite_note-7"><span class="mw-cite-backlink"><b><a href="#cite_ref-7">^</a></b></span> <span class="reference-text"><cite id="CITEREFReisinger2011" class="citation web cs1">Reisinger, Don (June 28, 2011). <a rel="nofollow" class="external text" href="https://www.cnet.com/news/geohot-now-a-facebook-employee/">"Geohot now a Facebook employee"</a>. <i><a href="CNET" title="CNET">CNET</a></i><span class="reference-accessdate">. Retrieved <span class="nowrap">January 10,</span> 2018</span>.</cite></span>
</li>
<li id="cite_note-8"><span class="mw-cite-backlink"><b><a href="#cite_ref-8">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://facebook.com/whitehat">"Facebook: Whitehat"</a>. <a href="Facebook" title="Facebook">Facebook</a><span class="reference-accessdate">. Retrieved <span class="nowrap">January 10,</span> 2018</span>.</cite></span>
</li>
<li id="cite_note-9"><span class="mw-cite-backlink"><b><a href="#cite_ref-9">^</a></b></span> <span class="reference-text"><cite id="CITEREFNakashimaRucker2017" class="citation news cs1">Nakashima, Ellen; Rucker, Philip (December 19, 2017). <a rel="nofollow" class="external text" href="https://www.washingtonpost.com/world/national-security/us-set-to-declare-north-korea-carried-out-massive-wannacry-cyber-attack/2017/12/18/509deb1c-e446-11e7-a65d-1ac0fd7f097e_story.html">"U.S. declares North Korea carried out massive WannaCry cyberattack"</a>. <i><a href="The_Washington_Post" title="The Washington Post">The Washington Post</a></i><span class="reference-accessdate">. Retrieved <span class="nowrap">January 10,</span> 2018</span>.</cite></span>
</li>
</ol></div></div></div><!--htdig_noindex--><div><div class="zim-footer">
This article is issued from <a class="external text" title="Last edited on 2024-04-02" href="https://en.wikipedia.org/wiki/?title=Facebook_malware&oldid=1216786601">Wikipedia</a>. The text is available under <a class="external text" href="https://creativecommons.org/licenses/by-sa/4.0/deed.en">Creative Commons Attribution-Share Alike 4.0</a> unless otherwise noted. Additional terms may apply for the media files.
</div>
</div><!--/htdig_noindex--></div>
</div>
</main>
</div>
</div>
</div>
</body></html>