Business Insights
  • Home
  • Crypto
  • Finance Expert
  • Business
  • Invest News
  • Investing
  • Trading
  • Forex
  • Videos
  • Economy
  • Tech
  • Contact

Archives

  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • August 2023
  • January 2023
  • December 2021
  • July 2021
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019

Categories

  • Business
  • Crypto
  • Economy
  • Finance Expert
  • Forex
  • Invest News
  • Investing
  • Tech
  • Trading
  • Uncategorized
  • Videos
Apply Loan
Money Visa
Advertise Us
Money Visa
  • Home
  • Crypto
  • Finance Expert
  • Business
  • Invest News
  • Investing
  • Trading
  • Forex
  • Videos
  • Economy
  • Tech
  • Contact
Facebook users are unknowingly promoting shady posts after clicking booby-trapped images hidden deep inside dangerous SVG files on adult websites
  • Tech

Facebook users are unknowingly promoting shady posts after clicking booby-trapped images hidden deep inside dangerous SVG files on adult websites

  • August 13, 2025
  • Roubens Andy King
Total
0
Shares
0
0
0
Total
0
Shares
Share 0
Tweet 0
Pin it 0


  • Malicious SVG files are being weaponized to secretly like Facebook posts without user consent
  • Attackers hide obfuscated JavaScript in images to bypass detection and execute dangerous social media hijacks
  • Trojan.JS.Likejack silently boosts targeted Facebook posts by exploiting active sessions of unsuspecting victims

Security researchers have uncovered dozens of adult websites which are embedding malicious code inside Scalable Vector Graphics (.svg) files.

Unlike common image formats such as JPEG or PNG, SVG files use XML text to define images, which can include HTML and JavaScript.

This feature makes SVG suitable for interactive graphics but also opens the door for exploitation through attacks like cross-site scripting and HTML injection.


You may like

How the clickjacking attack works

Research from Malwarebytes found selected visitors to these websites encounter booby-trapped SVG images.

When clicked, the files run heavily obfuscated JavaScript code, sometimes using a hybrid version of a technique known as “JSFuck” to disguise the script’s true purpose.

Once decoded, the code downloads further JavaScript, ultimately deploying a payload identified as Trojan.JS.Likejack.

If the victim has a Facebook session open, the malware silently clicks “Like” on a targeted post without consent, boosting its visibility in social feeds.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

The boost in visibility increases the chances that the targeted post will appear in more users’ feeds, effectively turning unsuspecting visitors into promoters without their knowledge.

The abuse of SVG files is not new. Two years ago, pro-Russian hackers exploited the format to carry out a cross-site scripting attack against Roundcube, a webmail platform used by millions.

More recently, phishing campaigns have used SVG files to open fake Microsoft login screens pre-filled with victims’ email addresses.

Researchers found many of these attacks originate from interconnected websites, often hosted on platforms like blogspot[.]com, and sometimes offering explicit celebrity images likely generated by artificial intelligence.

Facebook routinely shuts down accounts involved in such abuses, but those behind the campaigns often return with new profiles.

As more regions introduce age verification rules for adult content, some users may turn to less-regulated sites that deploy aggressive promotion tactics.

How to stay safe

The effect of this campaign goes beyond unwanted social media interactions. These tactics can be used for more harmful purposes, including identity theft or credential harvesting.

Experts recommend using updated security suites that can detect and block suspicious domains.

Also, ensure that your system has a properly configured firewall to prevent unauthorized data transfers.

Real-time protection can help identify threats before they execute, and awareness of file formats capable of running code is essential.

While using a VPN can help maintain privacy, it is not a substitute for strong endpoint protection and cautious online behavior.

Above all – be careful about what you click on the internet.

You might also like

Total
0
Shares
Share 0
Tweet 0
Pin it 0
Roubens Andy King

Previous Article
Bitcoin extends rally, hits record high above 4,000
  • Finance Expert

Bitcoin extends rally, hits record high above $124,000

  • August 13, 2025
  • Roubens Andy King
Read More
Next Article
Iconic restaurant closing forever after 52 years
  • Trading

Iconic restaurant closing forever after 52 years

  • August 13, 2025
  • Roubens Andy King
Read More
You May Also Like
Disney Settles FTC Complaint With YouTube Over Children’s Data Collection
Read More
  • Tech

Disney Settles FTC Complaint With YouTube Over Children’s Data Collection

  • Roubens Andy King
  • September 3, 2025
This HP laptop with an astonishing 32GB of RAM is just 1
Read More
  • Tech

This HP laptop with an astonishing 32GB of RAM is just $261

  • Roubens Andy King
  • September 3, 2025
Hot deal: Samsung Galaxy S25 Edge plummets to record-low price!
Read More
  • Tech

Hot deal: Samsung Galaxy S25 Edge plummets to record-low price!

  • Roubens Andy King
  • September 3, 2025
007 First Light looks like a hit, man
Read More
  • Tech

007 First Light looks like a hit, man

  • Roubens Andy King
  • September 3, 2025
Amazon’s Tomb Raider series will star Sophie Turner as Lara Croft
Read More
  • Tech

Amazon’s Tomb Raider series will star Sophie Turner as Lara Croft

  • Roubens Andy King
  • September 3, 2025
Orchard Robotics, founded by a Thiel fellow Cornell dropout, raises M for farm vision AI 
Read More
  • Tech

Orchard Robotics, founded by a Thiel fellow Cornell dropout, raises $22M for farm vision AI 

  • Roubens Andy King
  • September 3, 2025
Meta launches an Instagram app for the iPad, 15 years after its mobile app; it is slightly different than the mobile app, opening directly to a feed of Reels (Mia Sato/The Verge)
Read More
  • Tech

Meta launches an Instagram app for the iPad, 15 years after its mobile app; it is slightly different than the mobile app, opening directly to a feed of Reels (Mia Sato/The Verge)

  • Roubens Andy King
  • September 3, 2025
Acer Swift Air 16 laptop weighs less than 1kg, with a 16-inch screen, up to 32GB memory, and up to 1TB storage
Read More
  • Tech

Acer Swift Air 16 laptop weighs less than 1kg, with a 16-inch screen, up to 32GB memory, and up to 1TB storage

  • Roubens Andy King
  • September 3, 2025

Recent Posts

  • Fidelity’s $203 million debut puts Ethereum’s tokenized bills on $10B trajectory for 2025
  • REX-Osprey Solana ETF crosses $200M milestone as SOL hits seven-month high
  • SolarEdge Technologies (SEDG) Sees a More Significant Dip Than Broader Market: Some Facts to Know
  • Nick Szabo Confirmed as Keynote Speaker of Ethereum’s DEVCON1
  • Microsoft to Sponsor Ethereum’s DEVCON1
Featured Posts
  • Fidelity’s 3 million debut puts Ethereum’s tokenized bills on B trajectory for 2025 1
    Fidelity’s $203 million debut puts Ethereum’s tokenized bills on $10B trajectory for 2025
    • September 12, 2025
  • REX-Osprey Solana ETF crosses 0M milestone as SOL hits seven-month high 2
    REX-Osprey Solana ETF crosses $200M milestone as SOL hits seven-month high
    • September 12, 2025
  • SolarEdge Technologies (SEDG) Sees a More Significant Dip Than Broader Market: Some Facts to Know 3
    SolarEdge Technologies (SEDG) Sees a More Significant Dip Than Broader Market: Some Facts to Know
    • September 12, 2025
  • Nick Szabo Confirmed as Keynote Speaker of Ethereum’s DEVCON1 4
    Nick Szabo Confirmed as Keynote Speaker of Ethereum’s DEVCON1
    • September 12, 2025
  • Microsoft to Sponsor Ethereum’s DEVCON1 5
    Microsoft to Sponsor Ethereum’s DEVCON1
    • September 12, 2025
Recent Posts
  • Nasdaq notches record high close, traders look to Fed meeting
    Nasdaq notches record high close, traders look to Fed meeting
    • September 12, 2025
  • Mid-Sized Bitcoin Holders Break Records With 65K BTC Weekly Accumulation
    Mid-Sized Bitcoin Holders Break Records With 65K BTC Weekly Accumulation
    • September 12, 2025
  • Bitcoin Price Flashes ‘Rarest Signal’ Ever, Is A 100% Rally Possible?
    Bitcoin Price Flashes ‘Rarest Signal’ Ever, Is A 100% Rally Possible?
    • September 12, 2025
Categories
  • Business (2,057)
  • Crypto (1,679)
  • Economy (123)
  • Finance Expert (1,687)
  • Forex (1,678)
  • Invest News (2,362)
  • Investing (1,599)
  • Tech (2,056)
  • Trading (2,024)
  • Uncategorized (2)
  • Videos (817)

Subscribe

Subscribe now to our newsletter

Money Visa
  • Privacy Policy
  • DMCA
  • Terms of Use
Money & Invest Advices

Input your search keywords and press Enter.