Adult Sites Use Malware-Laced SVG Files to Hijack Facebook Likes

Image by franco alva, from Unsplash

Adult Sites Use Malware-Laced SVG Files to Hijack Facebook Likes

Reading time: 2 min

As more countries require age verification on adult websites, some shady adult sites are using sophisticated malware tricks to promote themselves on Facebook.

In a rush? Here are the quick facts:

  • Trojan.JS.Likejack silently clicks “Like” on Facebook without user consent.
  • SVG files can contain harmful JavaScript, not just images.
  • Many promoted sites claim AI-generated explicit celebrity images.

Security researchers at Malwarebytes discovered that dozens of adult websites use hidden malicious code in SVG image files, leading users to “Like” Facebook posts without their consent.

The attackers do this by embedding dangerous JavaScript code within the SVG graphic files, which can contain both pictures, as well as  malicious scripts.

“When one of these people clicks on the image, it causes browsers to surreptitiously register a like for Facebook posts promoting the site,” explains ArsTechnica. “The user will have to be logged in on Facebook for this to work, but we know many people keep Facebook open for easy access,” said Malwarebytes researcher Pieter Arntz.

The malicious code is heavily disguised using a method called “JSFuck,” which turns the JavaScript into confusing text, making detection difficult. Once triggered, it downloads a Trojan, named ‘‘Trojan.JS.Likejack,’’ which starts to silently click on adult content posts to increase their visibility throughout Facebook.

Many of the promoted sites claim to show explicit celebrity photos, often generated by AI, and are hosted on free blogging platforms like blogspot.com.

The attackers exploit the misconception that SVG files represent harmless images to execute their campaign. The combination of HTML and JavaScript code within SVG files transforms them into dangerous tools for cyberattacks.

Facebook regularly shuts down abusive accounts, but the malicious profiles frequently return, making this an ongoing problem.

Did you like this article? Rate it!
I hated it I don't really like it It was ok Pretty good! Loved it!

We're thrilled you enjoyed our work!

As a valued reader, would you mind giving us a shoutout on Trustpilot? It's quick and means the world to us. Thank you for being amazing!

Rate us on Trustpilot
0 Voted by 0 users
Title
Comment
Thanks for your feedback