Adult sites are stashing exploit code inside racy .svg files
The obfuscated code inside an .svg file downloaded from one of the porn sites.
Credit:
Malwarebytes
The obfuscated code inside an .svg file downloaded from one of the porn sites.
Credit:
Malwarebytes
Once decoded, the script causes the browser to download a chain of additional obfuscated JavaScript. The final payload, a known malicious script called Trojan.JS.Likejack, induces the browser to like a specified Facebook post as long as a user has their account open.
“This Trojan, also written in Ja...
Read more at arstechnica.com