Anaconda coughs up a hippo? It's a Facebook scam spreading virally

Filed Under: Data loss, Social networks, Spam, Video

Fake video thumbnail
Yet another rogue Facebook application is spreading its tentacles rapidly across the social networking system, posting messages from users' compromised accounts claiming to be a link to a video of an anaconda coughing up an entire hippo.

A quick search on Facebook finds thousands of users who appear to have updated their status with the message about "the scariest snake ever":

OMG, this is the biggest and scariest snake I have ever seen, check out this video

followed by a tiny.cc link.

As you can see in the following video, clicking on the link takes the unsuspecting Facebook user to a rogue application.

(Enjoy this video? You can check out more on the SophosLabs YouTube channel and subscribe if you like)

The rogue application tricks the user into giving it permission to access their Facebook profile, list of friends and be allowed to post status updates and messages onto their profile (which can then be seen by their Facebook friends).

Anaconda rogue application on Facebook

The point of the application's spamming is to draw Facebook users into taking online surveys - and each time a victim completes a survey, the scammer makes some commission. Even if you don't take the survey, the rogue application has already abused your Facebook account - changing your status message and spreading an advert for the alleged "shocking video" to your news feed:

SHOCKING! Anaconda Coughs Up An Entire Hippo!
Horrifying snake killed a huge hippo! SHOCKING! Video

Anaconda coughs up hippo messages

The other important thing here, of course, is how are you going to protect yourself in the future. Clearly many people need to be helped determining what is safe and what isn't safe behaviour on a social network - and education about new breaking threats is a great way to raise awareness.

If you have Facebook friends who you believe are acting unsafely online invite them to join the Sophos page on Facebook.

, , , ,

Leave a Reply

Your email address will not be published. Required fields are marked *

*

You may use these HTML tags and attributes: <a href="" title="" rel=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <pre> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

About the author

Graham Cluley is senior technology consultant at Sophos. The readers of Computer Weekly voted him security blogger of the year in 2009 and 2010, and he pipped Stephen Fry to the title of "Twitter user of the year" too. Which was nice. He was also named "Best Security Blogger" by the readers of SC Magazine in 2011. You can email Graham, subscribe to his updates on Facebook, follow him on Twitter and circle him on Google Plus for regular updates.