HomeSecurityFlyTrap malware hacks thousands of Facebook accounts!

FlyTrap malware hacks thousands of Facebook accounts!

FlyTrap malware, a new threat for Android, has hacked Facebook accounts in more than 140 countries, stealing session cookies.

FlyTrap hacking campaigns rely on simple social engineering tactics to trick victims into using their Facebook passwords to log in to malicious apps which then steal data related to their social media sessions.

See Also: Great Reset and Cryptocurrency – Technology and the Great Reset

FlyTrap malware hacks thousands of Facebook accounts!
FlyTrap malware Facebook

Researchers at mobile security firm Zimperium discovered the new malware and found that the stolen information was accessible to anyone who located FlyTrap's command and control (C2) server.

The FlyTrap hacking campaigns have been running since at least March. The hacker(s) used malicious apps with high-quality design, distributed through Google Play and third-party Android stores.

The lure included offers for free coupon codes (for Netflix, Google AdWords) and votes for famous football teams or highly recognizable football players, in view of UEFA Euro 2020.

Receiving the promised reward required logging into the app using Facebook credentials, while authentication takes place on the legitimate social media domain.

See Also: Gigabyte ransomware attack: Intel and AMD affected!

FlyTrap malware hacks thousands of Facebook accounts!
FlyTrap malware Facebook

Since the malicious apps use Facebook's authentic single sign-on (SSO) service, they cannot collect user credentials. Instead, FlyTrap relies on JavaScript injection to collect other sensitive data.

Using this technique, the application opens the legitimate URL within a WebView configured with JavaScript code injection capability and extracts all necessary information, such as cookies, user account details, location, and IP address with JS code injection.

All information collected in this way goes to FlyTrap's C2 server. More than 10,000 Android users in 144 countries fell victim to this social engineering attack.

The statistics on the percentage of compromised accounts come directly from the command and control server, which researchers were able to access because the database of stolen Facebook session cookies is available online.

See Also: Hackers compromise private routers – List of vulnerable devices

FlyTrap malware hacks thousands of Facebook accounts!
FlyTrap malware Facebook

Zimperium's Aazim Yaswant reported in a recent blog post that FlyTrap's C2 server had multiple security vulnerabilities that made it easier to access stored information.

The researcher notes that accounts on social networking platforms are a common target for hackers, who can use them for illegal actions, such as increasing the popularity of pages, websites, products, misinformation or political messaging.

He also emphasizes that phishing pages that steal credentials are not the only way to log in to an online service account. Logging in to the legitimate domain can also pose risks.

"High-quality graphics and official-looking login screens are common tactics to trick users into unknowingly providing sensitive information. In this case, while the user is logged into their official account, the FlyTrap Trojan hijacks the session information," said Aazim Yaswant, Android malware researcher, Zimperium.

Despite not being based on any new technique, FlyTrap managed to hack a significant number of Facebook accounts. With a few modifications, it could be transformed into a dangerous threat for mobile devices.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS