Initially I wasn’t going to blog about this, as I didn’t want to appear to be on a run of Facebook related posts. However this has been ongoing for over a week now, this same rogue app keeps reappearing, several of my own friends have fallen victim, so a warning seems like a good idea!
  
The rogue Facebook app in question has appeared for at least the third time in the space of a week and is clearly designed to fool victims into clicking the spam notifications it sends out, in order to earn the scammer some cash through affiliate based advertising.
  
The app is named “Like” and borrows the icon from the official Facebook “Likes” function. The Spam notifications it sends out have also been designed to resemble the real Facebook functionality. The name of the application contained in the Facebook URL has equally been designed to fool each time, it has been ”im_best_app”, “farn_ville” and “pet_villeik” respectively.
  

Rogue app Facebook notification

Rogue app Facebook notification.


 
 
If you click the link in the notification you are invited to allow the rogue app access to “your profile information, your photos, your friends’ info and other content it requires to work”. Of course with the app having ‘borrowed’ so freely from official Facebook look and feel many otherwise cautious users are falling for the ruse.
  

Rogue app "Like".

Rogue app "Like".


 
 
If you do click the “Allow” button you will very briefly see an application page that simply reads “Error! Error! ERROR!” before being forwarded to an external (to Facebook) website hosted at Dizzy Networks.
  

Like Facebook app page

Like Facebook app page


 
 
Dizzy Networks is a “technology focused advertising company” whose advertisers are apparently “hand selected and control their campaigns to fully optimize your overall performance“. Although, if you were interested in signing up as an advertiser for Dizzy Networks you’ll need to be trusting because the terms and conditions that you must agree to are “coming soon”!
  
The page at Dizzy Networks contains only a JavaScript that redirects once more to the landing page at Zwinky proposing the installation of the Zwinky software. The URL of that landing page contains the partner ID ZJxdm493 which would perhaps identify the person behind the scam. At the very least it would appear that Zwinky may be paying out commission under false pretences and Facebook users are having their personal information put at risk.
  
Facebook staff have responded to user complaints and to the information that I have sent them very rapidly in the two previous cases and I am sure this third example will also be removed quickly. Wouldn’t it be great though if some mechanism could be put in place to protect their hundreds of millions of users proactively?


Bookmark
| More
This entry was posted on Saturday, 27. February 2010 and is filed under "Social Engineering, Web 2.0, spam". You can follow any responses to this entry with RSS 2.0. You can leave a response here, or send a trackback from your own site.

5 Comments to "Rogue Facebook app “Like” pushing Zwinky & MyWebSearch"

Myles:
Monday, April 25th 2010, 10:15 pm -> Monday, 15. March 2010 um 7:03 pm

There was a system in face that they had that users could protect themselves with. You USED to be able to opt out of the Facebook API, and I’d be as bold as to state that since this stopped being an option, it appears an upsurge of these malicious apps has come of it.

Privacy and Social Media – Part III: Facebook:
Monday, April 25th 2010, 10:15 pm -> Tuesday, 30. March 2010 um 10:37 pm

[...] Defcon 17 in 2009. You should also always be on guard for things that look “official”, but are not (Countermeasures [...]

Rogue Facebook app “Like” pushing Zwinky & MyWebSearch | Business Computing World:
Monday, April 25th 2010, 10:15 pm -> Wednesday, 7. April 2010 um 4:16 pm

[...] Link to the original site [...]

Does Facebook Need Its Own Anti-Malware Service? | Technology and Web 2.0:
Monday, April 25th 2010, 10:15 pm -> Tuesday, 25. May 2010 um 5:24 pm

[...] scam (a rogue app with 25 variations, claiming it could tell you who visited your profile), the rogue “Like” app (which borrows the infamous “like” icon) and many others. Other unpatched attack [...]

We Love Crowds » Does Facebook Need Its Own Anti-Malware Service?:
Monday, April 25th 2010, 10:15 pm -> Tuesday, 25. May 2010 um 5:56 pm

[...] scam (a rogue app with 25 variations, claiming it could tell you who visited your profile), the rogue "Like" app (which borrows the infamous "like" icon) and many others. Other unpatched attack vectors, pop up [...]


Name:

E-Mail (not published)

Website:


Spam protection


© Copyright 2010 Trend Micro Inc. All rights reserved.
Legal Notice | Disclaimer