Warning: Don’t Click That Facebook Video Link – It’s a Trap!
Security experts at Kaspersky Lab have uncovered a nasty new scam on Facebook Messenger. Users are receiving video links that look like they’re from friends. But clicking them leads to fake websites designed to trick you into installing malicious software.
How the Scam Works
The crooks behind this campaign use hacked accounts, hijacked browsers, or clever clickjacking to spread their nasty links. The message usually says “name Video” with a suspicious bit.ly link. When you click it, you’re redirected to a dodgy site showing a fake video thumbnail that looks real.
From there, it gets worse. Depending on your device and browser, you’re sent to different fake update pages:
- Firefox on Windows: Fake Flash Player update page pushes a Windows adware download.
- Chrome users: A site mimics YouTube and shows bogus error pop-ups, tricking you to install a malicious Chrome extension from the Google Web Store.
- Mac OS X Safari: Fake Flash Media Player update that drops Mac adware (.dmg file) if clicked.
- Linux users: Redirected to a tailored fake update page for Linux systems.
The dodgy Chrome extension acts as a downloader, secretly fetching files chosen by the hackers. This malware isn’t banking Trojans or ransomware – it’s adware designed to rake in cash through junk adverts.
Facebook Spam: Not New, But Still Dangerous
Facebook spam campaigns have been around for years. Previously, hackers hid malware in plain sight, like dangerous .JPG files that unleashed Locky ransomware – locking victims’ files until they paid up. This new scam is just the latest trick to target unsuspecting users.
Stay Safe: Here’s What You Need to Do
- Don’t click video or image links from anyone without confirming with them first.
- Be wary of messages that seem off, even if they come from friends.
- Keep your software and security tools up to date and patched against threats.
Stay alert and don’t let cyber crooks cash in on you. If it looks dodgy, it probably is – so better safe than sorry!