Categorized | Facebook

More Likejacking: This Guy Took A Picture Of His Face Everyday For 8 Years

Since posting about the Justin Bieber likejacking campaign, we have observed similar campaigns cropping up.

Apparently, This Guy Took A Picture Of His Face For 8 Years

Apparently, This Guy Took A Picture Of His Face Every Day For 8 Years

Most recent and notable is a new campaign, which purports to showcase a time lapse video of a man that took a picture of his face everyday for 8 years. From the power of celebrity to outrageous and shocking headlines, scammers have managed to strike the right chord for luring in users.  This particular version shows just how successful they are.

Similar to the Justin Bieber campaign, there seems to be multiple versions of this one floating around.  In addition, the multiple versions all seem to reside on the “.info” top-level domain.

Look Familiar? Same Template for FouTube found in the Justin Bieber "Likejack" Campaign

Look Familiar? Same Template for FouTube found in the Justin Bieber "Likejack" Campaign

The user is presented with the same template we’ve seen before of a Fake YouTube (FouTube) page.  The end result is no different – the users’ mouse click is hijacked and they automatically “like” this page, which is then posted to their Facebook Wall and reaches the news feeds of their friends and family. Once again, there is a survey component to this, which helps put money into the pockets of the scammers.

However, what’s different this time around is that this version also tries to push the Free iPad/iPhone 4 scam.

Pushing the Free iPad scam onto Likejacking Victims

Pushing the Free iPad scam onto Likejacking Victims

Unfortunately, there is no such thing as a Free iPad/iPhone 4. While the site above claims to have over 800,000 likes, in actuality, less than 100 people have actually liked the scam page.

This was discovered late last night and our research indicated there were at least 9 versions of it floating around. As of this morning, 3 of those are no longer active (the .info sites remain up, the social graph components have been disabled).  The remaining 6 versions continue to fool users into clicking through, racking up more likes than the Justin Bieber campaign.

6 Active Versions of This Likejacking Campaign Remain

6 Active Versions of this Likejacking Campaign Remain

The reason for so many different versions is simple – strength in numbers. Going from 9 active versions to 6 still allows the campaign to spread, as showcased above.  Garnering over 220,000 “likes” for one page would have raised some red flags and may have been taken down quickly. Having multiple versions out there allows these pages to stay active longer, giving them more time to spread and to fool more users.

We continue to urge Facebook users to remain skeptical of posts such as these.  Warn your friends and family about these scams, and if someone you know has fallen for one, tell them to remove the post from their Facebook Wall and warn their friends and family about it.  Knowledge is power, and so long as users are unaware of these types of scam campaigns, the more difficult it will be to stop them from spreading.

Related Posts
  • This year’s Defcon badge has a persistent display
    It's one of the best things about the Defcon hacking conference, and one of its most closely guarded secrets: the programmable badge that's handed out to show attendees every year. View full post o...
  • shocktube.info is a scam!
    Beware, this site was reported involved with a scam and Likejacking activity. The spam was spread on Facebook, with a message like this: UNFASSBAR! ... Ich hab jeden Respekt vor Miley Cyrus verlore...
  • “The Hottest & Funniest Golf Course Video” scam has more than 200,000 likes on Facebook
    Right now there's a scam making its way across Facebook linking to a video titled "The Hottest & Funniest Golf Course Video - LOL" (example screen shot below). Websense customers are...
  • One more Adobe 0-day vulnerability using Office files
    Today Adobe announced a new 0-day vulnerability (CVE-2011-0611) in Adobe Flash Player and Adobe Acrobat that, similar to the previous 0-day from less than a month ago, was found embedded in a Microsof...
  • More on the “massive” SQL injection attack
    Alas, the news was published on April 1st. But it is not a joke. Curious, I spent a bit of time today researching it (when I really was supposed to be doing other things), and while the “lizamoon” ...
  • Facebook HTTPS is a Bit More Done…
    Our February 23rd post noted that Facebook's SSL "Secure Browsing" preferences had some issues remaining persistent. There's been some encouraging progress since then, and this is now what happ...
  • Very bad news, with more bad news embedded
    Malware writers never miss the chance to take advantage of big world events, no matter how tragic. The recent Japanese nuclear incident, caused by the devastating earthquakes, is their target this ti...
  • If you forward this email…
    Posted by Carlos Arias, March 2011 It is not unusual to receive alarming emails warning that your email service will shortly be shut down or your favorite social networking site will no longer be free...
  • More Browser Updates
    Well, actually we expect some more updates as some security vulnerabilities have been revealed at the Pwn2Own contest during the CanSecWest security conference. Google is the first and pushes out vers...
  • Facebook Likejacking, phishing and spam
    Last Thursday, I wrote about Facebook Likejacking. Today, similar pages were brought to my attention. They use Likejacking to spread through user profiles using much more aggressive spam techniques. ...

Comments are closed.

Security Status

Beware Facebook "Timeline" scams http://t.co/W5EW0cVv
5 months ago
Nigerian government (unknowingly) hosts phishing website http://t.co/uQd42ENw
5 months ago
PCMag Awards McAfee All Access its Editors’ Choice: SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today announced... http://t.co/FakV7Vd8
5 months ago
RT @mikko: I hadn't noticed Google Maps has added 3D models of buildings. Here's a (very accurate) view of F-Secure HQ in Helsinki http://t.co/IKfAZlak
5 months ago
North Koreans aren't known for their online presence. But others may be lured into clicking Kim Jong-Il 'videos' too http://t.co/yQOon6YT
5 months ago
How to Protect Your Professional Reputation on Facebook Timeline http://t.co/I4bcR2VN
5 months ago
This is pretty impressive from @Softpedia: Facebook scans 2 trillion link clicks and blocks 220 million posts each day http://t.co/vKsn9gNl
5 months ago
Need for integrated approach to security in industrial control systems - http://t.co/tPBCNOow with @PikeResearch
5 months ago
Some free-based music we play at work http://t.co/xu5agZfc
5 months ago
Japan’s cyber defense weapon: a virus. It includes quotes by @Luis_Corrons via @InfosecurityMag
5 months ago