Check Point says that hackers have been focused on finding exploits in social networks because they are usually “white listed.” The firm’s research found that hackers have found “a new capability to embed malicious code into an image file and successfully upload it to the social media website.” When a victim clicks on the image, the image is automatically downloaded. When the image is opened, the ransomware automatically locks up all their data and leaves a text file in each encrypted directory. That file points to servers on the anonymising Tor network where the victim can make a payment to get their shit back.

Advertisement

For now, Check Point says that they aren’t releasing full technical details until they know the problem has been fixed. They say they informed Facebook and LinkedIn back in September. Those are the only two social networks that they mention by name but they do not specify if those are the only two that are being used for attacks.

Basically, just know that if you click an image on social media and it automatically downloads you shouldn’t open it. And don’t open image files with “unusual extensions such as SVG, JS or HTA.”

Advertisement
Advertisement

Tell your grandmother it’s called ImageGate. Image. Gate.

[Check Point via Ars Technica]