Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity

    Attacking the Attackers: Facebook Hacker Tools Exploit Their Users

    Written by

    Sean Michael Kerner
    Published September 8, 2016
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      For those who are looking to hack the Facebook accounts of others, there is a marketplace of Facebook Hacker tools that offer the promise of point-and-click ease. According to a new report from Blue Coat Elastica Cloud Threat Labs (BCECTL), the promise made by many Facebook Hacker tools is false.

      Rather than providing access to the Facebook accounts of others, BCECTL found that most Facebook Hacker tools only exploit the users of the tools.

      “The samples we have analyzed don’t perform any real Facebook hacking as opposed to what is being claimed,” Aditya Sood, director of Security and Elastica Cloud Threat Labs at Blue Coat Elastica, now part of Symantec, told eWEEK.

      BCECTL looked at multiple tools with various names, including Faceoff Facebook Hacker, Skull Facebook Hacker and Scorpion Facebook Hacker. The various tools can require the user to input their own Facebook credentials in order to gain some form of access.

      Sood explained that the way the tools typically work is they will ask the user of the tool to provide the Facebook profile ID to be hacked. After that, it displays some fake system-critical failure messages. Following the failure message, the tool will ask the user to provide an activation code to hack into the profile.

      “When a user clicks the button to obtain an activation code, the browser is redirected back to some unauthorized domain such as http://faceoffactivationcode.com/ that could lead to advertising which might be malicious in nature,” Sood said.

      The various Facebook Hacker tools are shared and promoted in various ways, including via an email phishing campaign. The attack is targeted against individuals that are interested in getting the private information of other users’ Facebook accounts, according to Sood.

      “However, we discovered this attack by analyzing the files hosted on Google Drive as a part of in-house activities to gather more intelligence and feeding that back into the [Blue Coat] product,” Sood said.

      Links to various Facebook Hacker tools were being actively distributed and shared on Google Drive. BCECTL reported the malicious Google Drive URLs to Google’s Safe Browsing report phish link: https://www.google.com/safebrowsing/report_phish/.

      “It’s hard to list the numbers, but we have discovered multiple instances [seven-plus] on Google Drive at the moment,” Sood said. “We haven’t checked on other cloud services or standard domains.”
      The Elastica CloudSOC platform can detect anomalies in the compromised cloud service accounts that are used to host these kinds of tools for abusing the cloud service for unauthorized activities, Sood adding that Symantec/BlueCoat has the ability to dissect the network traffic to look into threats and associated anomalies. Additionally, the Symantec/BlueCoat global threat intelligence network provides regular updates about the state of URLs, he said.

      The Facebook Hacker tools are distributed at minimal cost ($20 for two to three months) or free of charge, Sood said. He emphasized that the Facebook Hacker tools are not doing explicit Facebook hacking. Rather, they are stealing end-users’ Facebook account credentials, which can be further used to conduct additional sets of attacks, such as drive-by downloading through malicious link sharing in target accounts, stealing private information, phishing and spamming through Facebook messages.

      Although the report looked at Facebook Hacker tools, there are also similar tools available for Twitter that work the same way.

      “We have seen instances of several domains which claim to hack Twitter but end up in the same behavior,” Sood said.

      Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

      Sean Michael Kerner
      Sean Michael Kerner
      Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×