Security researchers at Bitdefender have discovered a new phishing scam that installs a malicious extension in the Chrome web browser in order to turn Facebook ‘likes’ into cash for cyber crooks.
The exploit begins with a malicious link embedded in spam email, says Bogdan Botezatu, a senior e-threat analyst at Bitdefender. The link ushers you to the Chrome Web Store, where you download an extension for a “business” Flash player—assuming you’re foolish enough to click on spam links.
Once this so-called “business” version of Flash is downloaded, it monitors your browser activity. When you land on a Facebook page with Chrome, the malware checks your browser cookies to see if you’re logged into Facebook. If you are, it will fetch a piece of Javascript code that tells the extension what to do with your account.
“They can run as many campaigns as they want,” Botezatu said in an interview. “All they have to do is fetch a new script.”
To read this article in full or to leave a comment, please click here
…read more
Source: FULL ARTICLE at PCWorld
