A new Android Trojan has hijacked more than 10,000 Facebook accounts by stealing session cookies, according to researchers at Zimperium. The malware uses social engineering to trick users into installing malicious apps from the Google Play Store and third-party app stores.
“The threat actors made use of several themes that users would find appealing such as free Netflix coupon codes, Google AdWords coupon codes, and voting for the best football (soccer) team or player,” Zimperium says. “Initially available in Google Play and third-party stores, the application tricked users into downloading and trusting the application with high-quality designs and social engineering.”
After the app is installed, the user is asked to log into their Facebook account. Notably, this attack uses Facebook’s legitimate single-sign-on portal rather than a credential phishing page.
Zimperium also discovered that the attackers had left their command-and-control server exposed to the public internet, so anyone could access the stolen information and use it in further social engineering attacks.
“Malicious threat actors are leveraging common user misconceptions that logging into the right domain is always secure irrespective of the application used to log in,” the researchers write. “The targeted domains are popular social media platforms and this campaign has been exceptionally effective in harvesting social media session data of users from 144 countries. These accounts can be used as a botnet for different purposes: from boosting the popularity of pages/sites/products to spreading misinformation or political propaganda.”
New-school security awareness training can enable your employees to follow security best practices.
Zimperium has the full story.
** Optrics Inc. is an Authorized KnowBe4 partner
Free Phishing Security Test
Would your users fall for convincing phishing attacks? Take the first step now and find out before the bad guys do. Plus, see how you stack up against your peers with phishing Industry Benchmarks. The Phish-prone percentage is usually higher than you expect and is great ammo to get budget.
- Immediately start your test for up to 100 users (no need to talk to anyone)
- Select from 20+ languages and customize the phishing test template based on your environment
- Choose the landing page your users see after they click
- Show users which red flags they missed, or a 404 page
- Get a PDF emailed to you in 24 hours with your Phish-prone % and charts to share with management
- See how your organization compares to others in your industry
Find out how affordable new-school security awareness training is for your organization. Get a quote now.
The original article can be found here: