If you find yourself in front of a suspicious message at Facebook that says "LOL", and contains a supposed image, avoid clicking on it. The message usually comes from your Facebook friends who are already victims of malware included as an attachment.
Trojan is known in Greece, as we had revealed it two weeks ago (here and here), and as we have said then, it has been developed by Greek or Greek developers.
This time we did not have the virus in our hands to analyze it, but according to the photo published by The Hacker News, the malicious user who wrote the malware is Greek.
See the code photo

Malware can steal your Facebok account details.
Trojan has started spreading through the FaceBook Messenger service and pretends to be from a friend. It mentions a simple "LOL" to provoke the recipient's curiosity and contains a zip file that appears to be a photo called "IMG_xxxx.zip."
If a FaceBook user opens IMG_xxxx.zip, they will discover a Java file: "IMG_xxxx.jar". The same Jar file is not a virus, but a malware factor, which actually starts downloading a file from a predefined Dropbox account (as shown in the code). After downloading, you install the malware as a service to the victim's system. It then spreads to the victim's friends, automatically sending a similar malicious message in the background.
To avoid detection by security software, malicious software is injected into legitimate processes running on the victim's system. In this way, malicious software continues to spread as a chain reaction in recent weeks.
Are you infected?
To test if you have been the victim of this attack, scan your entire system using a trusted and up-to-date antivirus. Change your Facebok password immediately (after you're sure your system is clean).
George is still wondering what he is doing here….


