Trusteer flags up Facebook malware scam
Security software vendor uncovers malware aimed at charity-minded Facebook users.

Trusteer has discovered a Citadel malware configuration that targets Facebook users with fake requests for donations to children's charities.
The security software firm said the aim of the scam is to steal credit card data from charity-minded members of the social networking site.
Once Facebook users have logged in, the Citadel injection displays a pop up that asks for a $1 donation to a children's charity. The unsuspecting user is then asked for his or her credit card information.
The malware is effective because it targets users by language. It also poses as legitimate, well-known charities in targeted countries.
The company said the malware has web-injection pages in five languages: English, Italian, Spanish, German and Dutch.
In the English-language version, the malware poses as a charity for impoverished Haitian children.
Meanwhile, the Italian version uses the Red Balloon campaign, which was set up to help fight child mortality in Italy.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"This attack illustrates the continuing customisation of financial malware and harvesting of credit card data from the global base of Facebook users," said Trusteer's chief technology officer, Amit Klein.
"Using children's charities as a scam makes this attack believable and effective. Meanwhile, the one dollar donation amount is low enough that virtually anyone can contribute if they chose. This is a well-designed method for stealing credit and debit card data on a massive scale," he added.
-
Cleo attack victim list grows as Hertz confirms customer data stolen
News Hertz has confirmed it suffered a data breach as a result of the Cleo zero-day vulnerability in late 2024, with the car rental giant warning that customer data was stolen.
By Ross Kelly
-
Lateral moves in tech: Why leaders should support employee mobility
In-depth Encouraging staff to switch roles can have long-term benefits for skills in the tech sector
By Keri Allan
-
Latest Meta GDPR fine brings 12-month total to more than €1 billion
News Meta was issued with two hefty GDPR fines for “forcing” users to consent to data processing
By Ross Kelly
-
"Unacceptable" data scraping lands Meta a £228m data protection fine
News The much-awaited decision follows the scraping of half a billion users' data and received unanimous approval from EU regulators
By Rory Bathgate
-
Meta notifies around 1 million Facebook users of potential compromise through malicious apps
News The vast majority of apps targeting iOS users appeared to be genuine apps for managing business functions such as advertising and analytics
By Connor Jones
-
Facebook business accounts hijacked by infostealer malware campaign
News Threat actors are using LinkedIn phishing to seize business, ad accounts for financial gain
By Rory Bathgate
-
Meta begins encrypting Facebook URLs, nullifying tracking countermeasures
News The move has made URL stripping impossible but will improve analytics
By Rory Bathgate
-
Meta hit with €17 million fine over multiple GDPR breaches
News The social media giant set aside over €1 billion in November to help it cope with potential fines arising from data protection investigations
By Zach Marzouk
-
Meta says Apple's iOS privacy changes will cost it $10 billion in 2022
News The company's CFO suggests Google "faces a different set of restrictions" because it pays Apple to remain the default iOS search engine
By Bobby Hellard
-
Google, Facebook fined €210 million for making it difficult for users to reject cookies
News Data regulator CNIL gives companies three months to provide a system for refusing cookies that is as easy as single click consent
By Zach Marzouk