Jump to content

Scammers Use Facebook and Google to Spread Malicious ‘Pirate’ Files


NelsonG

Recommended Posts

scamkey.jpgLast weekend we reported how scammers were sending DMCA notices to downrank game piracy sites.

Presumably, this was done to give their malware-infested pirate sites a better ranking in search results.

While our previous article focused on the abuse of takedown notices, the problem is much broader. In addition to removing content, scammers are also spamming many sites with messages that link people to their dubious pirate sites.

We spoke to a source who has followed this activity for quite a while and actively reported spam he found on medium.com, change.org, wattpad.com, github.com, bitly.com, deviantart.com, zendesk.com, soundcloud.com, ghost.org, hashnode.com, and elsewhere.

Most of these sites were very cooperative and cleaned up the mess soon after they were alerted.

“The list is really long, but what was great is that all these services immediately responded to my reports. Some of them implemented spam filters and medium.com even sent a t-shirt to thank me,” says our source, who prefers to remain anonymous.

Zendesk’s response
zendesk.jpg

With any type of spam, it’s impossible to eliminate the problem completely. However, our source says that some platforms are more receptive to reports than others. At Facebook and Google, this didn’t go so easily.

For months, scammers have used Facebook events to promote their malware or trojan links out in the open, through numerous accounts. In some cases, these events have been online for months, such as with this Fix Problem account.

This account lists many hundreds of events, which presumably link to pirated software, games, and other content. There are no events of course, but these listings help to increase SEO and give the associated sites a boost in traffic as well.

Fix problem?
fixproblems.gif

The problem is rather persistent. Our source says that he reported the issue in detail to Facebook, but that there’s been little improvement. Many of the reported events are still online today, and new ones keep appearing too.

A targeted search for “Just Cause” Facebook events created over the past week, shows dozens of results.

Targeted Google search
justcausegoo.jpg

Initially, the Facebook posts linked directly to the sites where the malware-content could be downloaded, but more recently they switched to Google groups. Perhaps because these links are harder to detect automatically.

People who follow these links don’t get a copy of free software, games, or movies. Instead, they’re downloading malware-infested files, although the landing page suggests otherwise.

A Just Cause landing page
justcausesun.png

Facebook events appears to be one of the favorite spamming tools, but Google groups are also frequently used. This issue was brought to Google’s attention weeks ago, in a rather detailed post in the webmaster help forum.

For weeks, many of the reported groups remained online and some still are at the time of writing. New ones are still appearing too, as shown below.

Just Cause?
causegroup.png

More recently, Google has flagged several postings but instead of removing them entirely, Google added a warning message.

TorrentFreak followed a few of the links that were provided in these spam posts and these indeed point to suspicious malware files, or worse. While this type of spamming activity is not new, Google, Facebook and others may want to take a closer look at how this can be dealt with properly.

Our source has made it somewhat of a personal crusade to go after the scammers. As he runs a pirate site of his own, he a has stake in the matter. Previousy his own links were taken down from Google and, as reported last week, he believes that this was a targeted action by the scammers.

A very detailed accounting of evidence and other information, shared with us, suggests that’s indeed the case, at least in some instances. It could of course be that there are more rogue actors.

In the background, this takedown issue has added fuel to a rivalry between ‘real’ pirate sites. Accusations were made back and forth, which resulted in one site shutting down and much more drama on top.

It’s impossible to verify any of the claims or accusations and there may be more things going on at once. What we can say, however, is that our source directly linked the takedown efforts to the type of scamming activity on Google, Facebook, and other sites.

Source: TF, for the latest info on copyright, file-sharing, torrent sites and more. We also have VPN reviews, discounts, offers and coupons.

Torrentfreak?d=yIl2AUoC8zA Torrentfreak?i=paYMcp9iX-Q:cvFGUSTeqYc:D
paYMcp9iX-Q

View the full article

Link to comment
Share on other sites

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Our picks

    • Wait, Burning Man is going online-only? What does that even look like?
      You could have been forgiven for missing the announcement that actual physical Burning Man has been canceled for this year, if not next. Firstly, the nonprofit Burning Man organization, known affectionately to insiders as the Borg, posted it after 5 p.m. PT Friday. That, even in the COVID-19 era, is the traditional time to push out news when you don't want much media attention. 
      But secondly, you may have missed its cancellation because the Borg is being careful not to use the C-word. The announcement was neutrally titled "The Burning Man Multiverse in 2020." Even as it offers refunds to early ticket buyers, considers layoffs and other belt-tightening measures, and can't even commit to a physical event in 2021, the Borg is making lemonade by focusing on an online-only version of Black Rock City this coming August.    Read more...
      More about Burning Man, Tech, Web Culture, and Live EventsView the full article
      • 0 replies
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
×
×
  • Create New...