A new info-stealing malware called FFDroider steals credentials and cookies stored in browsers to compromise victims' social media accounts.
Social media accounts, especially verified ones , have always been an attractive target for cybercriminals. Malicious users could use these accounts for various malicious activities (crypto scams, malware distribution, etc.).
See also: New Denonia malware targets AWS Lambda environments

These accounts are even more attractive when they have access to social media ad platforms, allowing attackers to use the stolen credentials to display malicious ads.
FFDroider malware is distributed via software cracks
The info-stealing malware FFDroider was detected and analyzed by Zscaler.
Researchers also examined its distribution methods and found that FFDroider is distributed through software cracks, free software, games, and other files downloaded from torrent sites.
When downloading and installing the above programs, the FFDroider malware is also installed, but it disguises itself as the Telegram desktop app to avoid detection.
Upon startup, the FFDroider malware will create a Windows registry key named “FFDroider.” This is what led to the name of the new info-stealing malware.

FFDroider malware: How does it work?
The FFDroid malware targets cookies and account credentials stored in Google Chrome (and Chrome-based browsers), Mozilla Firefox, Internet Explorer , and Microsoft Edge.

The theft and decryption result in cleartext usernames and passwords, which are then transferred via HTTP POST request to the C2 server: http[:]//152[.]32[.]228[.]19/seemorebty.
Main goal of the malware: Gaining access to social media accounts
The FFDroider malware is not interested in stealing all the credentials stored in browsers. Instead, the malware developers focus on stealing credentials for social media accounts and eCommerce sites, including Facebook, Instagram, Twitter, Amazon, eBay, Etsy, and the portal for the WAX Cloud wallet.
The goal is to steal valid cookies that can be used for authentication on these platforms.
See also: Fake Android shopping apps steal bank account logins
If authentication is successful, say on Facebook, the FFDroider malware retrieves all Facebook pages and bookmarks, the victim's number of friends, and their account billing and payment information from the Facebook Ads manager.
What can attackers do with this information? They could run malicious advertising campaigns on the platform and promote their malware to a larger audience.
If successfully logged into Instagram, the FFDroider malware will open the account editing page to get the account's email address, mobile phone number, username, password, and other details.
The malware's capabilities make it quite dangerous. The malware doesn't just try to steal credentials, it also tries to log into the platform and steal even more information.
See also: Phishing email informs about alleged WhatsApp voice messages
After stealing information and sending it to the C2 server, the FFDroid malware focuses on downloading additional modules from its servers at regular intervals.
Zscaler analysts haven't provided many details about these modules, but the ability to download other programs makes it even more dangerous.

How to protect yourself?
The truth is that users can avoid malware infections like FFDroiderby staying away from downloading and installing software cracks and other illegal programs. As an added precaution, downloads can be uploaded to VirusTotal to check if antivirus solutions detect it as malware.
Recently, credential and information stealing malware has been appearing more and more frequently in the threat landscape. This malware steals information using a variety of techniques.
More details can be found in the Zscaler report.
Source: Bleeping Computer
