Facebook users are being targeted by malicious hackers through postings on the popular Wall section of the social-networking site, according to security company Sophos.
The Wall, a core feature of Facebook profile pages, is used by members to leave each other messages that in addition to text can also contain photos, videos, music and links to websites.
The malware attack comes in the form of a Wall message supposedly posted by a friend that urges members to click on a link to view a video on a website supposedly hosted by Google, said Graham Cluley, senior technology consultant for Sophos.
However, the link takes users to a web page that isn't hosted by Google, where they are told they need a new version of Adobe's Flash player and are urged to download an executable file to watch the video.
The file is really a Trojan horse, Troj/Dloadr-BPL, that funnels other malicious code detected as Troj/Agent-HJX into users' machines. Once it has done that, it displays an image of a court jester sticking his tongue out.
While on the surface this might seem a practical joke from a friend, in reality it means the PC has been compromised and malicious hackers have gained control over it to use it for a variety of purposes, such as sending spam or distributing malware. "They now own your PC," Cluley said.
Malicious hackers have been employing this malware distribution technique for many years on email messages, so many users know to avoid these traps. However, people may be less vigilant in more closed and controlled environments such as social-networking sites.
For example, in this case, the malicious Wall message is masked as coming from someone on the user's list of Facebook friends, increasing the likelihood that the link will be clicked on. "Be very suspicious of Wall postings asking you to click on a link to go watch a video," he said.
The friend whose name appears with the video has had his PC or Facebook account compromised in some way that lets malicious hackers perform actions without the friend's knowledge. It's possible that the affected friend previously fell for the "court jester" trap, and his PC and Facebook accounts are being used to propagate the scheme, he said.
The attack is the latest in a rising trend of malicious hackers using social-networking sites to distribute malware. These sites offer an attractive distribution channel because people feel safer and are more willing to follow links and perform actions if they think a friend is urging them to do so. In fact, it could be a malicious hacker posing as a friend,
If people click on a third-party website link and a message pops up asking them to download software into their machines, they should never go ahead with the software download. If they feel they should upgrade their Flash player, they should do so only from Adobe's website, Cluley said.
The news is also relevant for IT departments of companies where employees are allowed to use Facebook at work, Sophos said.