Cybercriminals Imitating Social Networks To Spread Malware

##AUTHORSPLIT##<--->

Research by a security product vendor shows that cybercriminals are using domain names that reference popular social networking sites to lure users to fake Web sites. The results of research conducted by Websense, which makes security software, reveals a growing domain-name cloning trend that includes brands like Facebook, MySpace, and Twitter. These sites have no connection to the real sites but are trying to trick unsuspecting users to visit fake Web sites and enter sensitive information or download malicious code.

The Websense Security Labs found more than 150,000 phony copycat sites using the term Facebook and 50,000 using some variation of either MySpace or Twitter in their URLs.

Researchers said hackers appear to be taking steps to create these cloned domains to circumvent security measures put in place by organizations to filter the original domain in a business setting. Many of the domains are proxy avoidance sites that are used to try to evade traditional Web filtering technology.

"These new threats illustrate that attackers will continue to target Facebook, MySpace, and Twitter, along with other social networking sites, for three reasons," said Charles Renert, senior director, advanced content research. "First, these Web sites are popular so fraudsters are able to target lots of victims; second, people trust the content on it because they think it's from other people in their network; and third, they are easy to compromise because they allow anybody to create and post content. Traditional Web filtering isn't enough to protect users from threats on trusted sites and isn't enough to keep up with fraudsters generating new URLs almost instantaneously to avoid detection. Only real-time analysis of Web content can prevent users from being exploited by these attacks."

This isn't the first time Facebook users have been targeted by hackers. In late April, Websense detected a phishing campaign targeting the site. The scam, labeled "FBStarter" by security researchers, redirected users to a phishing page that spoofs Facebook's sign-in page. By entering their user name and password, they unknowingly gave attackers the information necessary to log into their account and spam their friends.

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • DreamBox Math

    Discovery Education Announces Updates to Experience, DreamBox Math

    K-12 learning solution provider Discovery Education has announced enhancements to its Discovery Education Experience and DreamBox Math products, designed to create a more personalized, engaging learning experience for students.

  • abstract pattern of cybersecurity, ai and cloud imagery

    Report Identifies Malicious Use of AI in Cloud-Based Cyber Threats

    A recent report from OpenAI identifies the misuse of artificial intelligence in cybercrime, social engineering, and influence operations, particularly those targeting or operating through cloud infrastructure. In "Disrupting Malicious Uses of AI: June 2025," the company outlines how threat actors are weaponizing large language models for malicious ends — and how OpenAI is pushing back.

  • digital dashboard featuring a shield icon, graphs, a world map, and network nodes

    IBM Launches Agentic AI Governance and Security Platform

    IBM has introduced a new software stack for enterprise IT teams tasked with managing the complex governance and security challenges posed by autonomous AI systems.

  • laptop and fish hook

    Security Researchers Identify Generative AI 'Vishing' Attack

    A new report from researchers at Ontinue's Cyber Defense Center has identified a complex, multi-stage cyber attack that leveraged social engineering, remote access tools, and signed binaries to infiltrate and persist within a target network.