How Images Can Infect Your Computer through Social Media

How Images Can Infect Your Computer through Social Media Featured Image

If you are moderately tech savvy, whenever you hear of a system being infected, you normally think of an executable piece of code that has somehow hijacked its most secure functions. Infections can spread in any number of ways, but one thing remains certain: The link between viruses and executable code is so strong we don’t necessarily believe we have to protect ourselves from file types such as JPEGs, PNG images, and MP3 files. Or do we? Contrary to the previous assertion, the first two file types I’ve mentioned have been used to infect computers through social media messaging systems on Facebook and LinkedIn, as reported by Jon Fingas for Engadget on 27 November 2016.

What’s Going On?

lockymalware-email

On 18 February 2016 Symantec found a rather strange piece of software that turned out to be a new variant of ransomware spreading through the web (if you do not know what ransomware is, refer to this). This particular strain – known as Locky – spread through spam emails with attachments at a rate of roughly ten to twenty thousand victims per week between January and March 2016. It’s not necessarily shocking to see viruses spread this way. Email messages with ZIP attachments have been the go-to inoculation strategy since the early 90s.

Then, something else happened.

Towards the end of November 2016, users on Facebook and LinkedIn began seeing messages sent with image attachments. They seem rather safe, but when opened they revealed a new strain of Locky that would encrypt the system’s files and unlock them only if the victim paid a ransom of anywhere between US$200 and $400. The most shocking part of this was that the virus spread through images rather than conventional executed code.

Not Everything Is As It Seems

lockymalware-facebook

Although images are certainly being used to infect people on social media, it’s not quite how it looks! I’ve taken a little bit of a deeper look at the mechanism of Locky and its slippery ways, and it looks like there’s more to the story than a bunch of JPEGs that are “out to get you.”

First off, what you’re distributing when you send the malware to someone is the impression that you’re giving someone an image on social media. There’s a flaw in Facebook and LinkedIn’s code that allows certain files to be transferred with the image icon, leading the recipient to believe that they received a harmless picture of someone’s pet cat or new garden. What the recipient actually downloads is an HTA file, a very old executable program for Windows that has been around since 1999 (another item to add to the list of reasons why software in the 90s was completely bonkers).

Basically, HTA applications are like EXEs except they are layered on top of “mshta.exe” and were used by administrators to rapidly make changes to systems. Since they have the full “trust” of the system they are running on, they are free to wreak any amount of havoc that their code allows them to.

How to Prevent Infection

Once you’re infected with Locky, there’s not much you can do except hope you find an anti-malware application that can remove it while you’re booted in Safe Mode. But preventing the infection in the first place is rather easy. When you receive an image file on Facebook, and it doesn’t have a preview like the image below, then you’re probably going to be prompted to download it.

lockymalware-preview

Once you’ve downloaded the file, check its extension. If it doesn’t say JPG, JPEG, PNG, or anything that looks like it’s an image, it’s probably a virus. We’ve seen Locky in HTA format, but it could also appear in other types of executable codes (.COM, .PIF, .SCR, .CPL, .JAR, .APPLICATION, .EXE, .MSI, etc.). Just keep an eye out for file extensions and be wary of anything you don’t recognize. One surefire way to check whether the file you received is an image is by seeing if Windows Explorer gives you a preview when you change the display style to “Large Icons.”

Have any other nifty pieces of advice to share? Tell us in a comment!

Subscribe to our newsletter!

Our latest tutorials delivered straight to your inbox

Miguel Leiva-Gomez Avatar

Read next

Suzanne Simard sealed paper birch and Douglas fir seedlings inside plastic bags, fed them carbon-14 and carbon-13 dioxide, and nine days later found carbon had crossed between species through fungal threads in the British Columbia soil beneath her boots
A species of jellyfish called Turritopsis dohrnii can revert its adult cells back to a juvenile polyp stage when injured or starving, effectively restarting its life cycle, and biologists have so far failed to identify any natural limit to how many times it can do this.
A Japanese man named Jiroemon Kimura, who lived to 116, was born in 1897 when Queen Victoria still ruled and died in 2013, meaning a single human life personally overlapped with the invention of the airplane, the atomic bomb, the internet, and Instagram
The Hollywood sign originally read HOLLYWOODLAND when it was built in 1923 as a real estate advertisement for a housing development, and it was only meant to stand for 18 months, but nobody ever got around to taking it down and the city eventually adopted it as a landmark
Almost all of the world’s internet traffic does not travel by satellite but through fibre-optic cables lying on the ocean floor, a hidden web of wires crossing the deepest parts of the sea to connect the continents.
People who flip their phone face down on every table aren’t being secretive. They figured out that staying interruptible meant handing their time to whoever rang first
Twitch vs. Facebook Gaming vs. YouTube Gaming: What’s the Best Live Game Streaming Platform?
Chrome Extensions Ownership Transfer is a Direct Threat to You: How to Stay Safe