Ramnit worm goes social, steals Facebook passwords
Posted on 05.01.2012
Ramnit - the file-infecting, financial-data-stealing worm that has been around since April 2010 - has been modified again and is now bent on stealing Facebook login credentials, warn the researchers of security company Seculert.

They discovered the fact after having accessed one of the command and control servers to which the worm sends the stolen credentials, and have seen and exfiltrated a list of 45,000 credentials (mostly from users in the UK and France), which the consequently delivered to Facebook.

"We suspect that the attackers behind Ramnit are using the stolen credentials to log-in to victims' Facebook accounts and to transmit malicious links to their friends, thereby magnifying the malware's spread even further," say the researchers.

"In addition, cybercriminals are taking advantage of the fact that users tend to use the same password in various web-based services (Facebook, Gmail, Corporate SSL VPN, Outlook Web Access, etc.) to gain remote access to corporate networks."

This variant and this capability of the Ramnit worm are quite new. When it first appeared, the worm concentrated its efforts on infecting .EXE, .SCR, .DLL., .HTML and other types of files and stealing FTP credentials and browser cookies.

Last year Trusteer warned that the worm had acquired the ability to inject HTML code into a web browser, which it is using to bypass two-factor authentication and transaction signing systems used by financial institutions to protect online banking sessions. By reverse-engineering samples of this variant, the researchers found the method used to configure Ramnit to target a specific bank is identical to the one used by Zeus.






Spotlight

Cloned, booby-trapped Dark Web sites steal bitcoins, login credentials

Apart from being a way for dissidents and journalists to do their business without being spotted and identified by "the powers that be", the Dark Web is also a place where criminals sell and buy illegal wares and services and, apparently, where they also get robbed by scammers.


Weekly newsletter

Reading our newsletter every Monday will keep you up-to-date with security news.
  



Daily digest

Receive a daily digest of the latest security news.
  
DON'T
MISS

Fri, Jul 3rd
    COPYRIGHT 1998-2015 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //