Ramnit worm goes social, steals Facebook passwords
Posted on 05.01.2012
Ramnit - the file-infecting, financial-data-stealing worm that has been around since April 2010 - has been modified again and is now bent on stealing Facebook login credentials, warn the researchers of security company Seculert.

They discovered the fact after having accessed one of the command and control servers to which the worm sends the stolen credentials, and have seen and exfiltrated a list of 45,000 credentials (mostly from users in the UK and France), which the consequently delivered to Facebook.

"We suspect that the attackers behind Ramnit are using the stolen credentials to log-in to victims' Facebook accounts and to transmit malicious links to their friends, thereby magnifying the malware's spread even further," say the researchers.

"In addition, cybercriminals are taking advantage of the fact that users tend to use the same password in various web-based services (Facebook, Gmail, Corporate SSL VPN, Outlook Web Access, etc.) to gain remote access to corporate networks."

This variant and this capability of the Ramnit worm are quite new. When it first appeared, the worm concentrated its efforts on infecting .EXE, .SCR, .DLL., .HTML and other types of files and stealing FTP credentials and browser cookies.

Last year Trusteer warned that the worm had acquired the ability to inject HTML code into a web browser, which it is using to bypass two-factor authentication and transaction signing systems used by financial institutions to protect online banking sessions. By reverse-engineering samples of this variant, the researchers found the method used to configure Ramnit to target a specific bank is identical to the one used by Zeus.


MagSpoof: A device that spoofs credit cards, disables chip-and-PIN protection

The device can wirelessly spoof credit cards/magstripes, disable chip-and-PIN protection, and predict the credit card number and expiration date of Amex cards after they have reported stolen or lost.

Weekly newsletter

Reading our newsletter every Monday will keep you up-to-date with security news.

Daily digest

Receive a daily digest of the latest security news.

Thu, Nov 26th