Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

April 11th, 2011, 08:53 GMT · By

Twilight Breaking Dawn-Themed Scam Circulating on Facebook

SHARE:

Adjust text size:


Twilight Breaking Dawn game used as lure in Facebook scam
Enlarge picture
Security researchers warn of a new Facebook scam that uses a Twilight Breaking Dawn game as lure to trick users into spamming their friends and participate in surveys.

The scam combines clickjacking with rogue apps, so it comes with two propagation mechanisms. The produced spam encourages users to go play a new game based on the final part of the Twilight series.

It reads: "Be the first of your friends to play the awesome new Twilight game on Facebook!" and contains a link to a page displaying a poster with a "Play Now" button.

Clicking anywhere on the page forces users to like it and at the same time post the spam message without authorization on their walls.

This is achieved via an attack technique known as clickjacking, where a button is hidden and positioned over a legitimate-looking one so that clicks are hijacked and used to perform unintended actions.

Following the clickjacking, users are prompted to allow a rogue app called "Breaking Dawn" to post on their walls. If installed, this app gives scammers a more persistent way of sending spam from their victims' accounts.

Finally, users who get this far are asked to fill out a survey, allegedly as an account verification method. These surveys earn scammers money through affiliate marketing schemes that pay them commissions.

"It seems that fans of Twilight are only too easy pickings for Facebook scammers, judging by the large number of reports from affected Facebook users we are seeing today," writes Graham Cluley, a senior technology consultant at Sophos.

Users who fell victim to this scam should remove the rogue app from the profile by going to Account > Privacy Settings > Applications and Websites. The spam message posted on their wall should also be deleted and the rogue page unliked.

TELL US WHAT YOU THINK:

1,430 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


New Profile Views Scam Spotted on Facebook

Localized Facebook Scams on the Rise

Over 100,000 Facebook Users Fall Victim to Italian Likejacking Attack

Facebook Survey Scam's Lifespan Increased by Rogue Firefox Extension

Sexy Teacher Facebook Clickjacking Leads to Survey Scams

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM