45,000 stolen Facebook logins found

Powered by SC Magazine
 

Ramnit virus variant harvested login credentials to a single server.

The ever-evolving Ramnit worm is back, and has harvested more than 45,000 Facebook login credentials primarily from users in the UK and France.

Seculert Research Lab discovered a command-and-control (C&C) server holding the pilfered data in  an open directory called "Facebook," with a text file called "Facebook accounts".

Seculert CTO Aviv Ruff said the file contained more than 45,000 unique Facebook usernames and passwords.

"We suspect that the attackers behind Ramnit are using the stolen credentials to expand the malware's reach," Seculert said.

The threat was first discovered in April 2010. Prior variants have infected Windows executable and HTML files, and stole stored data, including usernames, passwords, login credentials and browser cookies.

Previous strains also have functioned as a backdoor, enabling a cyber thief to gain control of an infected computer.

Last July, Symantec reported that Ramnit was the most-blocked malware, accounting for 17 percent of incidents.

A variant spread a month later that incorporated source code from the notorious Zeus trojan, rendering it a hybrid capable of stealing financial assets.

Seculert said it was able to "bypass two-factor authentication and transaction signing systems, gain remote access to financial institutions, compromise online banking sessions and penetrate several corporate networks."

Computers are infected through drive-by download attacks, which occur when users simply visit a malicious website and become infected without taking any action.

Machines also can be impacted if users click on rogue email links.

In the case of Facebook, once the attackers steal a user's login and password to the social networking site, they can access the victim's account to direct others to Ramnit.

Users should never click on suspicious links, even if posted by one of their friends on Facebook, Raff said. Also they should not share passwords across online accounts.

Seculert provided Facebook with all of the stolen credentials it detected on the Ramnit C&C servers.

This article originally appeared at scmagazineus.com

Copyright © SC Magazine, US edition


45,000 stolen Facebook logins found
 
 
 
Top Stories
The True Cost of BYOD - 2014 survey
Twelve months on from our first study, is BYOD a better proposition?
 
Photos: Unboxing the Magnus supercomputer
Pawsey's biggest beast slots into place.
 
ANZ looks to life beyond the transaction
If digital disruptors think an online payments startup could rock the big four, they’ve missed the point of why people use banks, says Patrick Maes.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
What is delaying adoption of public cloud in your organisation?







   |   View results
Lock-in concerns
  29%
 
Application integration concerns
  3%
 
Security and compliance concerns
  28%
 
Unreliable network infrastructure
  9%
 
Data sovereignty concerns
  21%
 
Lack of stakeholder support
  3%
 
Protecting on-premise IT jobs
  4%
 
Difficulty transitioning CapEx budget into OpEx
  3%
TOTAL VOTES: 1068

Vote