Android malware allows attackers to hijack social media accounts

Researchers at Kaspesky have discovered two new Android malware modifications that, when combined, can steal cookies collected by user'...

Researchers at Kaspesky have discovered two new Android malware modifications that, when combined, can steal cookies collected by user's browsers and social media apps to allow an attacker to discreetly gain control over a victim's accounts.

Cookies are small pieces of data collected by websites in order to track a user's activity online to create personalized experiences in the future. In the wrong hands though, they can pose a security risk because cookies use a unique session ID that identifies users without requiring a password or login.

Once in possession of a user's ID, attackers can trick websites into thinking that they are that person and take control of their account. This is exactly what these two new Trojans with similar coding controlled by the same command and control (C&C) server do.

Stealing cookies

The first Trojan acquires root rights on a victim's device and this allows an attacker to transfer cookies from Facebook to their own servers. However, simply having a user's ID number is not enough to take control of an account in some circumstances. For instance, some websites have security measures in place that prevent suspicious log-in attempts.

This is where the second Trojan comes into play as it is a malicious app which can run a proxy server on a victim's device to bypass security measures to gain access without arousing suspicion. This allows an attacker to pose as the victim and take control of their social networking accounts to distribute undesirable content.

At this time, the aim of the cybercriminals stealing user's cookies is unknown but a page uncovered on the same C&C server may provide a hint. The page advertises services for distributing spam on social networks and messengers which means that attackers could be looking for account access as a means to launch widespread spam and phishing attacks.

Malware analyst at Kaspersky, Igor Golovin explained in a press release that while new, this threat will likely continue to grow, saying:

“By combining two attacks, the cookie thieves discovered a way to gain control over their victims’ accounts without arousing suspicions. While this is a relatively new threat—so far, only about 1000 individuals have been targeted—that number is growing and will most likely continue to do so, particularly since it’s so hard for websites to detect. Even though we typically don’t pay attention to cookies when we’re surfing the web, they’re still another means of processing our personal information, and anytime data about us is collected online, we need to pay attention.”



from TechRadar - All the latest technology news https://ift.tt/2TXIpKY
via IFTTT

COMMENTS

BLOGGER
Name

Apps,3858,Business,151,Camera,1155,Earn $$$,3,Gadgets,1741,Games,926,GTA,1,Innovations,3,Mobile,1697,Paid Promotions,5,Promotions,5,Sports,1,Technology,8106,Trailers,796,Travel,37,Trending,4,Trendly News,25335,TrendlyNews,125,Video,5,XIAOMI,13,YouTube - 9to5Google,124,
ltr
item
Trendly News | #ListenNow #Everyday #100ShortNews #TopTrendings #PopularNews #Reviews #TrendlyNews: Android malware allows attackers to hijack social media accounts
Android malware allows attackers to hijack social media accounts
Trendly News | #ListenNow #Everyday #100ShortNews #TopTrendings #PopularNews #Reviews #TrendlyNews
http://www.trendlynews.in/2020/03/android-malware-allows-attackers-to.html
http://www.trendlynews.in/
http://www.trendlynews.in/
http://www.trendlynews.in/2020/03/android-malware-allows-attackers-to.html
true
3372890392287038985
UTF-8
Loaded All Posts Not found any posts VIEW ALL Readmore Reply Cancel reply Delete By Home PAGES POSTS View All RECOMMENDED FOR YOU LABEL ARCHIVE SEARCH ALL POSTS Not found any post match with your request Back Home Sunday Monday Tuesday Wednesday Thursday Friday Saturday Sun Mon Tue Wed Thu Fri Sat January February March April May June July August September October November December Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec just now 1 minute ago $$1$$ minutes ago 1 hour ago $$1$$ hours ago Yesterday $$1$$ days ago $$1$$ weeks ago more than 5 weeks ago Followers Follow THIS PREMIUM CONTENT IS LOCKED STEP 1: Share. STEP 2: Click the link you shared to unlock Copy All Code Select All Code All codes were copied to your clipboard Can not copy the codes / texts, please press [CTRL]+[C] (or CMD+C with Mac) to copy