CYBER NEWS

Instagram Scam Alert – Profiles Hacked to Promote NSFW Content

Do you have an Instagram account which you use on a regular basis? If so, feel warned – there’s a trend of hacked Instagram profiles promoting adult content. This trend was spotted at the beginning of 2016 but is currently taking a turn to the worse. As reported by Symantec, scammers are hacking Instagram accounts and modifying profiles with sexually suggestive imagery to trick users into visiting adult dating and NSFW sites.

Instagram Campaign Similar to Previous Twitter Accounts Compromised for NSFW Content

Researchers point out that the current Instagram situation with profiles being hacked and exploited for the promotion of pornographic content resembles a previous case with Twitter accounts. However, a direct connection between the two hasn’t been established yet.

Related: Instagram Prone to Remote Code Execution

How to Spot a Hacked Instagram Account

There are several signs that hint of accounts being exploited by attackers:

  • Modified user name
  • Different profile image
  • Different profile full name
  • Different profile bio
  • Profile link changed/added
  • New photos uploaded

hacked-instagram-accounts-symantec-stforum

For one, the altered profile picture is usually changed to a photo of a woman, regardless of the sex of the account owner. Other sexually suggestive photos are also added to the profile. Furthermore, the hacked profile usually instructs the user to visit the profile link. The link is either a shortened URL or a direct link to the particular page.

The best way to learn that your Instagram account has been hacked is if you attempt to login but your password has been changed, without your knowledge. Researchers believe that the owners of hacked accounts move on to create new profiles, since the hacked ones endure in time.

Related: New Facebook Scam – Fake and Duplicate Accounts for Fraud

Interestingly, researchers have observed a slight simplification of the adult content scam. Some previously identified traits of compromised accounts are now missing, like no change in the name or no new photos uploaded. The reason for this “laziness” is not particularly clear.

Nonetheless, the campaign is definitely an example of affiliate-based spam. Researchers explain that “as with similar scams, the profile links redirect to an intermediary site controlled by the scammer.”

This site contains a survey suggesting that a woman has nude photos to share and that the user will be directed to a site that offers “quick sex” rather than dating. Interestingly, this page only appears on mobile browsers. If the user tries to visit the URLs on a desktop computer or laptop, they are sent to a random Facebook user’s profile.

Spam-Scams Compromise Other Social and Dating Networks, Too

We recently wrote about a similar scam affecting Tinder users, also denounced by Symantec. The scam involved the initiation of flirty conversations with playful opening messages like “Wanna eat cookie dough together some time?”. The spam bot would then “release” several messages, and then ask the user whether he had been verified by Tinder.

To avoid any of your user accounts being hacked and deployed for NSFW activities, sustain excellent password hygiene:

  • Use only complex passwords
  • Change your passwords frequently
  • Don’t recycle previously used passwords, be creative
  • Subscribe to Have I Been Pwned? to be notified of a breach
  • Employ 2FA whenever possible
  • Don’t reply to spam messages in your email inbox
  • Milena Dimitrova

    Milena Dimitrova

    An inspired writer and content manager who has been with SensorsTechForum since the beginning. Focused on user privacy and malware development, she strongly believes in a world where cybersecurity plays a central role. If common sense makes no sense, she will be there to take notes. Those notes may later turn into articles! Follow Milena @Milenyim

    More Posts

    Follow Me:
    Twitter

    Leave a Comment

    Your email address will not be published. Required fields are marked *

    Time limit is exhausted. Please reload CAPTCHA.

Share on Facebook Share
Loading...
Share on Twitter Tweet
Loading...
Share on Google Plus Share
Loading...
Share on Linkedin Share
Loading...
Share on Digg Share
Share on Reddit Share
Loading...
Share on Stumbleupon Share
Loading...