The Facebook Color Changer app promises users the ability to change the dominant color in their Facebook profile from the standard blue color. However, the app is not what it is supposed to be.
According to the Cheetah Mobile CM Security Researcher lab, the Color Changer app is actually a new kind of security threat in disguise, with the app targeting the users of the social network in the attempt of spreading malicious software, Techtimes reported.
Cheetah Mobile is naming the virus the Facebook Color Scam, in a post that the company wrote on its official blog.
There have been similar viruses posing as color changing apps on Facebook in the past, but Cheetah Mobile is the first company to discover the return of the scam.
According to Cheetah Mobile, the Facebook Color Scam has already affected 10,000 users in several countries.
The virus appears as a Facebook app that can be shared or posted on the News Feed. Once users click on the posted link, they are redirected to a phishing website.
Researchers at Cheetah Mobile discovered that the virus is exploiting a vulnerability that can be found in the app page of Facebook. The vulnerability allows hackers to implant malicious code and viruses into apps on Facebook, which then redirects users to the harmful phishing websites.
The code used by the Facebook Color Scam makes users believe that they are visiting the webpage "apps.facebook.com/themsandcolors," before automatically redirecting them to the phishing website.
Once the user lands on the phishing website, the hackers have two options of launching an attack. The first option is to steal the access tokens of the user by requesting them to watch a tutorial video on the fake color changer app. Once the user has watched the video, hackers can temporarily control the access tokens of the user, giving them the ability to connect with his or her Facebook contacts.
If the user declines to watch the video, the hackers use the second option of making the user download a malicious program. If the user is on a desktop computer, the website will redirect them to a download page for an improper video player. If the user is on an Android device, the website will show a warning message that states that the device has received an infection, and that the users should download a suggested app.
Users that have been tricked by the Facebook Color Scam may be able to circumvent the hack by first changing the password for the affected account. The user can then go to the app settings of Facebook and remove the color changer app from linking to their account.
GMT 10:39 2018 Tuesday ,09 January
Pay Dh50 and make internet calls on EtisalatGMT 22:01 2017 Tuesday ,31 October
Internet giants find more Russia-linked election meddlingGMT 21:31 2017 Tuesday ,31 October
Google ditched autopilot driving feature after test user napped behind wheelGMT 21:17 2017 Tuesday ,31 October
Tech firms must do more on extremism: World Economic ForumGMT 21:07 2017 Tuesday ,31 October
Swiping your way toward peace of mind: The most helpful breast cancer appsGMT 21:30 2017 Sunday ,29 October
VPN law latest step in Kremlin online crackdown, experts sayGMT 16:03 2017 Sunday ,22 October
'Good morning' Facebook post leads to arrest of PalestinianGMT 15:03 2017 Thursday ,12 October
Facebook pushes ad overhaul before 2018 US electionMaintained and developed by Arabs Today Group SAL.
All rights reserved to Arab Today Media Group 2023 ©
Maintained and developed by Arabs Today Group SAL.
All rights reserved to Arab Today Media Group 2023 ©