In May, the personal data of more than half a billion Facebook users was available for free download on an online hacking forum. EPA
In May, the personal data of more than half a billion Facebook users was available for free download on an online hacking forum. EPA
In May, the personal data of more than half a billion Facebook users was available for free download on an online hacking forum. EPA
In May, the personal data of more than half a billion Facebook users was available for free download on an online hacking forum. EPA

New Android malware compromises 10,000 Facebook accounts in 140 countries


Alkesh Sharma
  • English
  • Arabic

New malware called FlyTrap has compromised more than 10,000 Facebook accounts in about 140 countries since March, according to a new report.

FlyTrap has penetrated accounts through various tactics such as social media breaching, third-party app stores and malicious apps, according to US-based security company Zimperium. The malicious software primarily targeted victims using Google’s Android mobile operating system.

Zimperium’s zLabs mobile threat research team said its forensic evidence of this active attack points to malicious parties in Vietnam.

“These malicious applications were initially distributed through both Google Play and third-party application stores,” Zimperium said.

After the first detection, it reported the findings to Alphabet-owned Google, which verified the research findings and removed the malicious applications from the Google Play store.

“However, the malicious applications are still available on third-party, unsecured app repositories … highlighting the risk of side-loaded applications to mobile endpoints and user data,” the company said.

“The mobile application poses a threat to the victim’s social identity by hijacking their Facebook accounts via a Trojan [horse] infecting their Android device.”

The information collected from the victim’s Android device includes their Facebook ID, location, email address, intellectual property details of the device and other personal information associated with the Facebook account.

Facebook and Google did not respond to The National's request for comments.

How FlyTrap works?

The threat actors use several themes that users would find appealing such as free Netflix coupon codes, Google AdWords coupon codes and voting for the best football or cricket player.

“Initially available in Google Play and third-party stores, the [malicious] application tricked users into downloading and trusting it with high-quality designs and social engineering … after installation, the malicious application displays pages that engage the user and asks for a response from them,” Zimperium said.



Gothia Cup 2025

4,872 matches 

1,942 teams

116 pitches

76 nations

26 UAE teams

15 Lebanese teams

2 Kuwaiti teams

Specs

Engine: Dual-motor all-wheel-drive electric

Range: Up to 610km

Power: 905hp

Torque: 985Nm

Price: From Dh439,000

Available: Now

The biog

Name: Sari Al Zubaidi

Occupation: co-founder of Cafe di Rosati

Age: 42

Marital status: single

Favourite drink: drip coffee V60

Favourite destination: Bali, Indonesia 

Favourite book: 100 Years of Solitude 

How to invest in gold

Investors can tap into the gold price by purchasing physical jewellery, coins and even gold bars, but these need to be stored safely and possibly insured.

A cheaper and more straightforward way to benefit from gold price growth is to buy an exchange-traded fund (ETF).

Most advisers suggest sticking to “physical” ETFs. These hold actual gold bullion, bars and coins in a vault on investors’ behalf. Others do not hold gold but use derivatives to track the price instead, adding an extra layer of risk. The two biggest physical gold ETFs are SPDR Gold Trust and iShares Gold Trust.

Another way to invest in gold’s success is to buy gold mining stocks, but Mr Gravier says this brings added risks and can be more volatile. “They have a serious downside potential should the price consolidate.”

Mr Kyprianou says gold and gold miners are two different asset classes. “One is a commodity and the other is a company stock, which means they behave differently.”

Mining companies are a business, susceptible to other market forces, such as worker availability, health and safety, strikes, debt levels, and so on. “These have nothing to do with gold at all. It means that some companies will survive, others won’t.”

By contrast, when gold is mined, it just sits in a vault. “It doesn’t even rust, which means it retains its value,” Mr Kyprianou says.

You may already have exposure to gold miners in your portfolio, say, through an international ETF or actively managed mutual fund.

You could spread this risk with an actively managed fund that invests in a spread of gold miners, with the best known being BlackRock Gold & General. It is up an incredible 55 per cent over the past year, and 240 per cent over five years. As always, past performance is no guide to the future.

Updated: August 10, 2021, 6:34 AM