Facebook Malware: Color Change

0
195

One of the oldest Facebook scams has been resurrected to haunt the lives of over 10,000 users according to Cheetah Mobile.

Facebook color changer is an app that is said to be able to change the color of your Facebook page by a simple selection of colors much like those in the picture. However, the app does not do this and upon clicking on the link you are not taken to the URL you thought you were (apps.facebook.com/themsandcolors) it instead actually redirects you to another website that tries to gain access to your Facebook account. 

This is caused by a vulnerability in the Facebook app page that allows you to inject code to redirect the user to any page you wish. In this case you are redirected to a page that shows the viewer a video. The video is all about the app, however by doing so they steal the access tokens to your Facebook account. By doing so they can gain access to your friends list but don’t have complete control over the account.

If you refuse to watch the video then you will be redirected to another page to download an adult video player. If you happen to be on a mobile device then it will display a pop-up telling you that you are infected and that you need to download a malicious app in order to remove the malware that you don’t have.

The best thing is to avoid the app at all costs and to avoid clicking on any links relating to it that may show up in your news feed.

If You Already Have The App.

  1. Reset your password immediately. If you don’t use 2 step verification it is recommended to set this up.
  2. Remove the app from your Facebook account.
  3. Scan for malware on your computer using Malwarebytes.
  4. Share the message with your friends so they dont fall for the same trap that you did.

For Mobile Users

  1. Same as above.
  2. Same as above.
  3. Download and scan your device with 360 Mobile Security.
  4. Same as above.

If you have any questions about the malware how to remove it or anything else please ask in the comments below.

LEAVE A REPLY