Close Menu
VernoNews
  • Home
  • World
  • National
  • Science
  • Business
  • Health
  • Education
  • Lifestyle
  • Entertainment
  • Sports
  • Technology
  • Gossip
Trending

India’s Confidence Crisis Curbs Financial Engagement Despite High Access

March 24, 2026

Tour 1,440 Sq Ft Singapore Condo for Indian Family of Four

March 24, 2026

March 24 in History: Elizabeth I Dies, Germanwings Crash Kills 150

March 24, 2026

Vietnam Airlines Cuts Flights Amid Jet Fuel Shortage Crisis

March 24, 2026

Von der Leyen Warns of ‘Upside Down’ World in Australian Parliament Speech

March 24, 2026

Claude AI Now Executes Tasks Directly on macOS Devices

March 24, 2026

Trump Halts Iran Strikes for 5 Days Amid Talk Claims

March 24, 2026
Facebook X (Twitter) Instagram
VernoNews
  • Home
  • World
  • National
  • Science
  • Business
  • Health
  • Education
  • Lifestyle
  • Entertainment
  • Sports
  • Technology
  • Gossip
VernoNews
Home»Technology»Fb customers are unknowingly selling shady posts after clicking booby-trapped pictures hidden deep inside harmful SVG recordsdata on grownup web sites
Technology

Fb customers are unknowingly selling shady posts after clicking booby-trapped pictures hidden deep inside harmful SVG recordsdata on grownup web sites

VernoNewsBy VernoNewsAugust 14, 2025No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Reddit WhatsApp Email
Fb customers are unknowingly selling shady posts after clicking booby-trapped pictures hidden deep inside harmful SVG recordsdata on grownup web sites
Share
Facebook Twitter LinkedIn Pinterest WhatsApp Email

[ad_1]


  • Malicious SVG recordsdata are being weaponized to secretly like Fb posts with out consumer consent
  • Attackers conceal obfuscated JavaScript in pictures to bypass detection and execute harmful social media hijacks
  • Trojan.JS.Likejack silently boosts focused Fb posts by exploiting lively periods of unsuspecting victims

Safety researchers have uncovered dozens of grownup web sites that are embedding malicious code inside Scalable Vector Graphics (.svg) recordsdata.

Not like widespread picture codecs comparable to JPEG or PNG, SVG recordsdata use XML textual content to outline pictures, which may embrace HTML and JavaScript.

This function makes SVG appropriate for interactive graphics but in addition opens the door for exploitation by means of assaults like cross-site scripting and HTML injection.


Chances are you’ll like

How the clickjacking assault works

Analysis from Malwarebytes discovered chosen guests to those web sites encounter booby-trapped SVG pictures.

When clicked, the recordsdata run closely obfuscated JavaScript code, typically utilizing a hybrid model of a method referred to as “JSFuck” to disguise the script’s true objective.

As soon as decoded, the code downloads additional JavaScript, finally deploying a payload recognized as Trojan.JS.Likejack.

If the sufferer has a Fb session open, the malware silently clicks “Like” on a focused submit with out consent, boosting its visibility in social feeds.

Signal as much as the TechRadar Professional publication to get all the highest information, opinion, options and steering your online business must succeed!

The enhance in visibility will increase the possibilities that the focused submit will seem in additional customers’ feeds, successfully turning unsuspecting guests into promoters with out their data.

The abuse of SVG recordsdata will not be new. Two years in the past, pro-Russian hackers exploited the format to hold out a cross-site scripting assault towards Roundcube, a webmail platform utilized by thousands and thousands.

Extra not too long ago, phishing campaigns have used SVG recordsdata to open faux Microsoft login screens pre-filled with victims’ e-mail addresses.

Researchers discovered many of those assaults originate from interconnected web sites, typically hosted on platforms like blogspot[.]com, and typically providing express movie star pictures probably generated by synthetic intelligence.

Fb routinely shuts down accounts concerned in such abuses, however these behind the campaigns typically return with new profiles.

As extra areas introduce age verification guidelines for grownup content material, some customers could flip to less-regulated websites that deploy aggressive promotion ways.

The best way to keep protected

The impact of this marketing campaign goes past undesirable social media interactions. These ways can be utilized for extra dangerous functions, together with id theft or credential harvesting.

Consultants advocate utilizing up to date safety suites that may detect and block suspicious domains.

Additionally, be certain that your system has a correctly configured firewall to forestall unauthorized knowledge transfers.

Actual-time safety will help determine threats earlier than they execute, and consciousness of file codecs able to operating code is crucial.

Whereas utilizing a VPN will help preserve privateness, it isn’t an alternative to robust endpoint safety and cautious on-line habits.

Above all – watch out about what you click on on the web.

You may also like

[ad_2]

Avatar photo
VernoNews

    Related Posts

    Claude AI Now Executes Tasks Directly on macOS Devices

    March 24, 2026

    iPhone Air C1X Modem Matches Qualcomm X80, Leads in 5G Latency

    March 23, 2026

    5 GEO Strategies to Boost Brand Visibility in AI Search 2026

    March 23, 2026
    Leave A Reply Cancel Reply

    Don't Miss
    Business

    India’s Confidence Crisis Curbs Financial Engagement Despite High Access

    By VernoNewsMarch 24, 20260

    India’s financial sector provides widespread access to products, yet a confidence crisis among consumers hampers…

    Tour 1,440 Sq Ft Singapore Condo for Indian Family of Four

    March 24, 2026

    March 24 in History: Elizabeth I Dies, Germanwings Crash Kills 150

    March 24, 2026

    Vietnam Airlines Cuts Flights Amid Jet Fuel Shortage Crisis

    March 24, 2026

    Von der Leyen Warns of ‘Upside Down’ World in Australian Parliament Speech

    March 24, 2026

    Claude AI Now Executes Tasks Directly on macOS Devices

    March 24, 2026

    Trump Halts Iran Strikes for 5 Days Amid Talk Claims

    March 24, 2026
    About Us
    About Us

    VernoNews delivers fast, fearless coverage of the stories that matter — from breaking news and politics to pop culture and tech. Stay informed, stay sharp, stay ahead with VernoNews.

    Our Picks

    India’s Confidence Crisis Curbs Financial Engagement Despite High Access

    March 24, 2026

    Tour 1,440 Sq Ft Singapore Condo for Indian Family of Four

    March 24, 2026

    March 24 in History: Elizabeth I Dies, Germanwings Crash Kills 150

    March 24, 2026
    Trending

    Vietnam Airlines Cuts Flights Amid Jet Fuel Shortage Crisis

    March 24, 2026

    Von der Leyen Warns of ‘Upside Down’ World in Australian Parliament Speech

    March 24, 2026

    Claude AI Now Executes Tasks Directly on macOS Devices

    March 24, 2026
    • Contact Us
    • Privacy Policy
    • Terms of Service
    2025 Copyright © VernoNews. All rights reserved

    Type above and press Enter to search. Press Esc to cancel.