• Home
    • What is
    • Computer security
      • Windows security
      • Mac security
      • Linux security
    • Mobile security
      • Android security
      • iOS Security
    • Data security
    • SCCM
    • Reviews
      • Case studies
    • Advertise
    • Contact
      • Privacy Policy
  • Subscribe now

    Loading
  • Home
  • What is
  • Computer security
    • Windows security
    • Mac security
    • Linux security
  • Mobile security
    • Android security
    • iOS Security
  • Data security
  • SCCM
  • Reviews
    • Case studies
  • Advertise
  • Contact
    • Privacy Policy
Home » Breaking Computer security Latest Cybersecurity News

Chameleon attack can now manipulate your ‘likes’ on Facebook, Linkedin and Twitter

John Greenwood Posted On January 22, 2020
0



Chameleon attack

Cyberattacks are of different types with unique motives, this new attack in the industry manipulates users ‘likes’ on Online Social Networks (OSN) Facebook, Linkedin and Twitter. However, WhatsApp and Instagram are safe, while Reddit, Flickr and Tumblr could be vulnerable. 

The security researches Aviad Elyashar, Sagi Uziel, Abigail Paradise, and Rami Puzis from Ben-Gurion University of the Negev, Israel have discovered this OSN trickery called the Chameleon attack.

What is the Chameleon attack?

The link previews and redirected links in the OSN is taken advantage to alter the published content. This OSN based trickery lures users to like a malicious posts and alter itself to a different content/post after user’s action is called the Chameleon attack. 

If a user is lured to like a post or profile which he otherwise would not have done consciously is what Chameleon attack is intended to do. The attackers here create could create a fake profile or group, by-pass moderation filters, and confuse the moderators between the real and the Chameleon page. 

This flaw could impact users’ reputation and image by making them like unwanted posts or profiles. 

Five phases of the Chameleon attack

Five phases of chameleon attack

Reconnaissance: The attacker studies the victims’ area of interest and creates a fake post or page using the basic techniques. 

Weaponizing: Attacker uses the redirecting links to create one or more redirection chains to different sources.

Delivery: Phishing or spear-phishing attacks are used to attract the users attention.

Maturation: Chameleon material develops reliability within the social platforms, and then interact with the targeted victims. This is not a sophisticated attack, as the standard cyber kill chains do not consider them so, however, developing trust and reliability with social platforms could depend on the motive, targeted or untargeted Chameleon attacks

Execution: After all the above process, the attacker then alters the posts and profiles by redefining the redirect target links and refreshing the link previews.

The researchers have also published a research paper on this Chameleon attack. The below video shows the live execution of this attack in Facebook.

When this article was written, the researchers hadn’t identified any fix for this attack and had requested other security researchers to consider this Chameleon attack along with phishing, spear-phishing and related scam attacks while researching on the OSN vulnerabilities and security. Until a solution is identified users are requested to be careful of Chameleon posts and profiles in social medias.

Share the article with your friends


Chameleon attackChameleon cyberattack


Author

John Greenwood

He has been working with Cybersec and Infosec market for 12+ years now. Passionate about AI, Cybersecurity, Info security, Blockchain and Machine Learning. When he is not occupied with cybersecurity, he likes to go on bike rides!

Leave A Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

  • Subscribe to our newsletter

    Loading
  • Windows security

    • Top 9 Best Log Management Tools for 2025
      September 20, 2025
    • Top 4 Remote Support Tools for 2025- Best Remote Support...
      September 18, 2025
    • Top 5 Best Unified Endpoint Management (UEM) Software...
      September 12, 2025
    • Top 5 Threat Intelligence Tools For 2025
      July 25, 2025
    • Top 5 Best Microsoft Intune Alternatives to Consider...
      July 23, 2025


  • About us

    Our vision is to deliver the trending and happening cyber events to the enthusiasts.

    We believe in delivering educational and quality content for hassle-free understanding of the subject.

  • Subscribe to our newsletter

    Loading
  • Follow us

  • Advertise with us

    You can reach us via Facebook, Linkedin, or Twitter for advertising purposes.


© The Cybersecurity Times 2022. All rights reserved.
Press enter/return to begin your search