A new Windows information stealing malware dubbed FFDroider which is designed to steal usernames and passwords, along with cookies from infected computers are spotted by researchers.
FFDroider is mainly focused on stealing login credentials for social media websites, including Facebook, Instagram and Twitter, but it also steals passwords for Amazon, eBay and Etsy accounts. It can also steal cookies from Google Chrome, Mozilla Firefox, Internet Explorer and Microsoft Edge browsers.
According to the cybersecurity researchers at Zscaler, the information stolen by the trojan malware can be used to take control of accounts, steal personal information, commit fraud against victims, and could also provide attackers with a means of hacking other accounts if the same email and password is used to access them.
The researchers have observed “multiple” campaigns related to FFDroider, that are all connected to a malicious program embedded in cracked versions of installers and freeware.
The malware disguises itself as Telegram app in order to avoid being detected even though users who aren’t Telegram users might wonder why folders claiming to be that app have appeared.
Once installed on a system, the malware monitors the actions of the victim and when they enter their login details into the specified social media platforms – the information gets stolen. FFDroider also steals cookies and saved login credentials from the browser.
If stolen social media account credentials are linked to a business account, the malware also looks for billing information, potentially enabling the attackers to steal bank payment details.
The attackers could also use compromised Facebook or Instagram accounts of businesses to run malicious advertising campaigns, take control of additional accounts, steal more payment details, or spread the malware further.
In order to stay safe from this campaign, users must be cautious of unexpected emails claiming to offer free software – especially if that software is something that usually must be paid for, as it clearly indicates that the download link can’t be trusted.
The users are recommended to use multi-factor authentication across all social media platforms. In any situation if you think your password might have been stolen, you should change it immediately.

















Comments