Cybercriminals Imitating Social Networks To Spread Malware

##AUTHORSPLIT##<--->

Research by a security product vendor shows that cybercriminals are using domain names that reference popular social networking sites to lure users to fake Web sites. The results of research conducted by Websense, which makes security software, reveals a growing domain-name cloning trend that includes brands like Facebook, MySpace, and Twitter. These sites have no connection to the real sites but are trying to trick unsuspecting users to visit fake Web sites and enter sensitive information or download malicious code.

The Websense Security Labs found more than 150,000 phony copycat sites using the term Facebook and 50,000 using some variation of either MySpace or Twitter in their URLs.

Researchers said hackers appear to be taking steps to create these cloned domains to circumvent security measures put in place by organizations to filter the original domain in a business setting. Many of the domains are proxy avoidance sites that are used to try to evade traditional Web filtering technology.

"These new threats illustrate that attackers will continue to target Facebook, MySpace, and Twitter, along with other social networking sites, for three reasons," said Charles Renert, senior director, advanced content research. "First, these Web sites are popular so fraudsters are able to target lots of victims; second, people trust the content on it because they think it's from other people in their network; and third, they are easy to compromise because they allow anybody to create and post content. Traditional Web filtering isn't enough to protect users from threats on trusted sites and isn't enough to keep up with fraudsters generating new URLs almost instantaneously to avoid detection. Only real-time analysis of Web content can prevent users from being exploited by these attacks."

This isn't the first time Facebook users have been targeted by hackers. In late April, Websense detected a phishing campaign targeting the site. The scam, labeled "FBStarter" by security researchers, redirected users to a phishing page that spoofs Facebook's sign-in page. By entering their user name and password, they unknowingly gave attackers the information necessary to log into their account and spam their friends.

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • large cloud icon on the right in an abstract world above a polygon with a dark blue background

    Cloud Security Alliance Expands Agentic AI Governance Work

    The Cloud Security Alliance (CSA) has announced a series of CSAI Foundation milestones aimed at securing what it calls the agentic control plane, including a new catastrophic risk initiative, CVE Numbering Authority authorization, and the acquisition of two agentic AI specifications.

  • Neon email icon hangs from chain with fishing hook below.

    Report Emphasizes Importance of Building a Security Culture

    While security teams have invested heavily in e-mail protection, endpoint security, and identity controls, new research from Fortra suggests one challenge remains difficult to solve: users.

  • businessman holding tablet with holographic AI icons

    Google Moving AI Agents into Mainstream Product Portfolio

    At its recent I/O developer conference, Google positioned artificial intelligence agents not as a distant research project, but as a product strategy spanning Search, personal assistants, productivity software, developer tools, and smart glasses.

  • person typing on a touch screen schedule plan calendar

    Deadline Extended for ADA Title II Compliance

    Schools working to meet the Americans with Disabilities Act Title II regulations for digital accessibility have received a temporary reprieve: The United States Department of Justice has published an interim final rule to push back the compliance deadline by one year.