Legitimate websites are hacked and abused in this attack

Sep 3, 2013 22:46 GMT  ·  By

Cleverly designed fake Facebook emails are being used by cybercriminals to trick recipients into visiting malicious websites.

Entitled, “Hi [name], here are some pages you may like,” the emails read something like this: “Like these Pages to get updates in your News Feed.”

When users click on the “Find more pages” or the “Go to Facebook” buttons, they’re taken to one of many compromised websites.

ThreatTrack Security researchers have identified at least 9 legitimate websites from all over the world that have been compromised by the cybercriminals that run this scheme.

All of the affected sites have been set up to host the BlackHole exploit kit, which leverages vulnerabilities in visitors’ computers in an effort to push malware.

In case you come across such emails, make sure the buttons point to Facebook and not some other website.