Technology6.01.2012

Worm steals 45,000 Facebook logins

At least 45,000 Facebook accounts have been compromised after the Ramnit worm was used to steal their credentials.

Ramnit has been tracked by security company Seculert since its discovery in April 2010, who have noted that the worm has been used to “bypass two-factor authentication and transaction signing systems, gain remote access to financial institutions, compromise online banking sessions and penetrate several corporate networks.”

Microsoft describes Ramnit as a “multi-component malware that infects Windows executable files, Microsoft Office files and HTML files” in order to steal “sensitive information such as saved FTP credentials and browser cookies.”

Securlert recently discovered that 800,000 machines were infected by Ramnit between September and December 2011.

“We suspect that the attackers behind Ramnit are using the stolen credentials to log-in to victims’ Facebook accounts and to transmit malicious links to their friends, thereby magnifying the malware’s spread even further,” according to Seculert.

“In addition, cybercriminals are taking advantage of the fact that users tend to use the same password in various web-based services (Facebook, Gmail, Corporate SSL VPN, Outlook Web Access, etc.) to gain remote access to corporate networks.”

Read the full story at: Ars Technica.

Show comments

Latest news

More news

Trending news

Poll

Which ride-hailing service do you trust the most?

View Results

Loading ... Loading ...
Sign up to the MyBroadband newsletter