Anaconda coughs up a hippo? It’s a Facebook scam spreading virally

Fake video thumbnail
Yet another rogue Facebook application is spreading its tentacles rapidly across the social networking system, posting messages from users’ compromised accounts claiming to be a link to a video of an anaconda coughing up an entire hippo.

A quick search on Facebook finds thousands of users who appear to have updated their status with the message about “the scariest snake ever”:

OMG, this is the biggest and scariest snake I have ever seen, check out this video

followed by a tiny.cc link.

Sign up to our free newsletter.
Security news, advice, and tips.

As you can see in the following video, clicking on the link takes the unsuspecting Facebook user to a rogue application.

[youtube=http://www.youtube.com/watch?v=Dw1oDdPziAY&hl=en_GB&fs=1]

The rogue application tricks the user into giving it permission to access their Facebook profile, list of friends and be allowed to post status updates and messages onto their profile (which can then be seen by their Facebook friends).

Anaconda rogue application on Facebook

The point of the application’s spamming is to draw Facebook users into taking online surveys – and each time a victim completes a survey, the scammer makes some commission. Even if you don’t take the survey, the rogue application has already abused your Facebook account – changing your status message and spreading an advert for the alleged “shocking video” to your news feed:

SHOCKING! Anaconda Coughs Up An Entire Hippo!
Horrifying snake killed a huge hippo! SHOCKING! Video

Anaconda coughs up hippo messages

The other important thing here, of course, is how are you going to protect yourself in the future. Clearly many people need to be helped determining what is safe and what isn’t safe behaviour on a social network – and education about new breaking threats is a great way to raise awareness.

If you have Facebook friends who you believe are acting unsafely online invite them to join the Sophos page on Facebook.


Graham Cluley is an award-winning keynote speaker who has given presentations around the world about cybersecurity, hackers, and online privacy. A veteran of the computer security industry since the early 1990s, he wrote the first ever version of Dr Solomon's Anti-Virus Toolkit for Windows, makes regular media appearances, and is the co-host of the popular "The AI Fix" and "Smashing Security" podcasts. Follow him on Bluesky and Mastodon, or drop him an email.

What do you think? Leave a comment

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.