Experts at ESET security firm discovered a new variant of iBanking trojan which is exploiting Facebook as vector of infection. The malware is available for sale in the underground for $5,000 according the RSAs FraudAction Group, the malware is used to avoid the security mechanisms implemented by the banking websites, including two-factor authentication. The new variant uses JavaScript to inject content into Facebook web pages, in particular to create a fake Facebook Verification page for Facebook users. Once the victim logs into his Facebook account, the bot tries to inject the following content into the webpage : The above verification page that was designed to request victims, their mobile number in order to verify the Facebook account authenticity.”]
Source: https://securityaffairs.co/wordpress/24069/malware/ibanking-trojan-targets-facebook.html