The Reuters news agency reported earlier today a sudden increase in violent and pornographic images and videos on Facebook. A quick review of my personal account and a check-in with my other Facebook-wielding colleagues revealed a couple of nothing more than a couple of suggestive pictures, complete with snarky comments embedded in them, from the usual sources and no discussion of violence or pornography pandemics. While our collective Facebook usage is described as casual at best, it seems unusual that several dozen security researchers who keep an eye or two on Facebook wouldn’t have noticed something suspicious should there have been outbreaks of violence and pornography there. After all, if nothing else, it makes for good blog fodder.
Our colleagues at Sophos and BitDefender have written more about the matter in their respective blogs, with the former providing some additional details of what Facebook’s customers saw and the latter identifying a variant of the seven-year-old Win32/Bifrose trojan as the source of the problem and speculating that this might be a late arrival of the Fawkes virus that Anonymous claimed it was going to unleash on Facebook for Guy Fawkes Day.
Regardless of the history or scope of this threat, Facebook Security has not provided any updates on the matter, which leads ESET to believe that while the imagery spread by the trojan on Facebook may be disturbing, it’s effect is limited in scope and not cause for alarm.
As we do not have any specific countermeasures to share with you for this non-event, ESET would like to provide some prescriptive guidance about staying safe online, especially when using Facebook:
I would also like to refer readers of this blog to a couple of earlier articles in particular: In Facebook security updates – how to make your account more secure, ESET Researcher Cameron Camp gives step-by-step instructions on how to adjust your privacy settings in Facebook, while Armor for Social Butterflies provides more general guidelines about safely using social media sites such as Facebook and Twitter.
Aryeh Goretsky, MVP, ZCSE
Author Aryeh Goretsky, We Live Security