Home » News » Malware » Attention! Keylogger comes via rogue Facebook message

Attention! Keylogger comes via rogue Facebook message

By Gina on February 17, 2012 | Malware, rogue Facebook message, Microsoft Silverlight program, Facebook scam, Microsoft PIF file, Jorik Trojan Attention! Keylogger comes via rogue Facebook message

According to BarracudaLabs researchers, rogue Facebook message is hitting users' emails and brings scam for those who fall for fake message.

This counterfeit message contains only an image within which asks users to install Microsoft Silverlight program in order to see what the message is about. An email address is fabricated to trick people into falling for such scam and it is supposedly sent from Facebook. 



If you flicker with the mouse over the image you'll see that the file is a Microsoft PIF file which means it's executable one and that is hosted on a IP address in Malaysia. Unfortunately, this is the Jorik Trojan

Once you click on a button for downloading the file, you'll activate Trojan itself which starts recording every keystroke and web page title into a disk file which is sent to a C&C server that belongs to cybercriminals.

If you have security software onto your system you are safe from such infections because it catches potential threats but you still need to be vigilante because in most cases you can't even notice or suspect and download such infections by yourself. Keep safe!

More Malware news

Danger! Facebook private messages and Instant Messengers are infected by worm

Danger! Facebook private messages and Instant Messengers are infected by worm

According to TrendLabs, infected messages are spreading on Facebook which contain a malicious link pointing to an archive file “May09-Picture18.JPG_www.facebook.com.zip”. Zipped archive itself has a file titled “May09-Picture18.JPG_www.facebook.com” and uses the extension “.com”. Malware within is able to terminate services and processes related to AV which quickly shuts down AV from detection or removal of the worm. This detected malware is named WORM_STECKCT.EVL. Read more.


News categories

Latest news

Related news