HomeSecurityFFDroider malware: Steals credentials and cookies and compromises social media accounts

FFDroider malware: Steals credentials and cookies and compromises social media accounts

A new info-stealing malware called FFDroider steals credentials and cookies stored in browsers to compromise victims' social media accounts.

Social media accounts, especially verified ones , have always been an attractive target for cybercriminals. Malicious users could use these accounts for various malicious activities (crypto scams, malware distribution, etc.).

See also: New Denonia malware targets AWS Lambda environments

FFDroider malware

These accounts are even more attractive when they have access to social media ad platforms, allowing attackers to use the stolen credentials to display malicious ads.

FFDroider malware is distributed via software cracks

The info-stealing malware FFDroider was detected and analyzed by Zscaler.

Researchers also examined its distribution methods and found that FFDroider is distributed through software cracks, free software, games, and other files downloaded from torrent sites.

When downloading and installing the above programs, the FFDroider malware is also installed, but it disguises itself as the Telegram desktop app to avoid detection.

Upon startup, the FFDroider malware will create a Windows registry key named “FFDroider.” This is what led to the name of the new info-stealing malware.

malware credentials

FFDroider malware: How does it work?

The FFDroid malware targets cookies and account credentials stored in Google Chrome (and Chrome-based browsers), Mozilla Firefox, Internet Explorer , and Microsoft Edge.

social media malware

The theft and decryption result in cleartext usernames and passwords, which are then transferred via HTTP POST request to the C2 server: http[:]//152[.]32[.]228[.]19/seemorebty.

Main goal of the malware: Gaining access to social media accounts

The FFDroider malware is not interested in stealing all the credentials stored in browsers. Instead, the malware developers focus on stealing credentials for social media accounts and eCommerce sites, including Facebook, Instagram, Twitter, Amazon, eBay, Etsy, and the portal for the WAX ​​Cloud wallet.

The goal is to steal valid cookies that can be used for authentication on these platforms.

See also: Fake Android shopping apps steal bank account logins

If authentication is successful, say on Facebook, the FFDroider malware retrieves all Facebook pages and bookmarks, the victim's number of friends, and their account billing and payment information from the Facebook Ads manager.

What can attackers do with this information? They could run malicious advertising campaigns on the platform and promote their malware to a larger audience.

If successfully logged into Instagram, the FFDroider malware will open the account editing page to get the account's email address, mobile phone number, username, password, and other details.

The malware's capabilities make it quite dangerous. The malware doesn't just try to steal credentials, it also tries to log into the platform and steal even more information.

See also: Phishing email informs about alleged WhatsApp voice messages

After stealing information and sending it to the C2 server, the FFDroid malware focuses on downloading additional modules from its servers at regular intervals.

Zscaler analysts haven't provided many details about these modules, but the ability to download other programs makes it even more dangerous.

social media malware

How to protect yourself?

The truth is that users can avoid malware infections like FFDroiderby staying away from downloading and installing software cracks and other illegal programs. As an added precaution, downloads can be uploaded to VirusTotal to check if antivirus solutions detect it as malware.

Recently, credential and information stealing malware has been appearing more and more frequently in the threat landscape. This malware steals information using a variety of techniques.

More details can be found in the Zscaler report.

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS