News

Flaw in Facebook Messenger App Allows Attackers to Run Persistent Malware

Security researchers from Reason Labs disclosed a critical vulnerability in the Facebook Messenger application for Windows that could allow attackers to hijack a call within the Messenger code to inject malware. The researchers also stated that it is a persistent threat that provides hackers undetected access to the application. The flaw was discovered in Facebook Messenger version 460.16, however, it is now fixed by the social media giant with the updated version 480.5 after Reason Labs reported the issue.

According to Reason Labs, the flaw initiates a call to load Windows Powershell from the C:\python27 path, which is generated while downloading version 2.7 of Python, and does not exist in most of the Windows installations. Cybercriminals can hijack these calls to stealthily execute malware without administrator knowledge.

GIF Courtesy: Reason Labs

In order to test the bug, Reason Labs researchers created a reverse shell  with msfvenom and a listener with Metasploit.  The reverse shell was then renamed Powershell.exe and was installed into the Python directory (c:\python27). The researchers found that the vulnerable app triggered the call and executed the reverse shell, proving that potential attackers can abuse the flaw for persistent malware attacks.

GIF Courtesy: Reason Labs

It is better to be vigilant about the potential vulnerabilities in online applications for messaging and videoconferencing, and other remote working tools, as we are spending more time online since the beginning of the pandemic. Even Facebook reported a 70% rise in time spent on its apps since the outbreak and a 50% increase in messaging apps.

 

CISOMAG

Recent Posts

Cybersec Europe

May 21-22, 2025 Location: Brussels Expo, Belgium Website: https://shorturl.at/61nXS / Cybersec Europe 2025 – The…

3 days ago

HackVSIT 6.0

April 25-26, 2025 Location: New Delhi Website: https://hack-vsit.tech/ The romanticism of a legacy continued through…

3 days ago

CyberX Bahrain

April 23, 2025 Location: Bahrain Website: https://bahrain.cyberxglobal.com CyberX Summit & Awards 2025 - Bahrain Edition…

5 days ago

Infosecurity Europe

June 3-5, 2025 Location: ExCel London, UK Website: https://www.infosecurityeurope.com/ Celebrating its 30th anniversary this year,…

6 days ago

x33fcon

June 9-13, 2025 Location: Gdynia, Poland And Online Website: https://x33fcon.com/#!index.md Experience the Welcoming Spirit of…

2 weeks ago

IT Congress 2025

May 14-15, 2025 Location: Complex Senator, Timişoara, Romania Website: https://itcongress.ro/ IT Congress is the most…

2 weeks ago