George Mason University logo
Information Technology Unit homepage
Information Technology Security homepage

New Email Threats Target Facebook Users

The first threat is a malicious e-mail posing as a Facebook password reset confirmation. The email contains a .zip file attachment inside of which is an exe file. This exe file is malware and part of the Bredolab botnet threat. If you get this message, do not open the attachment. Please delete the email.

The email looks like the following:

---------------------------------------------------------------------------
Subject: Facebook Password Reset Confirmation. 
Attachments:Facebook_Password_c92dd.zip

Hey

Because of the measures taken to provide safety to our clients, your password has been changed.
You can find your new password in attached document.

Thanks,
The Facebook Team.

---------------------------------------------------------------------------

The second e-mail threat is a phishing attack. If you get this message, do not reply, do not click any links and do not provide any personal information. Please delete this e-mail.

The email looks like the following:

---------------------------------------------------------------------------
Subject: Facebook Account Update

Dear Facebook user,

In an effort to make your online experience safer and more enjoyable, Facebook will be implementing a new login system that will affect all Facebook users. These changes will offer new features and increased account security.
Before you are able to use the new login system, you will be required to update your account.
Click here to update your account online now.

If you have any questions, reference our New User Guide.

Thanks,
The Facebook Team
Update your Facebook account

---------------------------------------------------------------------------