Ramnit worm heads for Facebook
Contributed by: Email on 01/05/2012 04:19 PM
[
Comments
]
The worm was originally discovered in April of 2010 by Microsoft security who describes it as Win32/Ramnit is a family of multi-component malware that infects Windows executable files, Microsoft Office files and HTML files. Win32/Ramnit spreads to removable drives, steals sensitive information such as saved FTP credentials and browser cookies. The malware may also open a backdoor to await instructions from a remote attacker.
In August 2011 (yes, over a year later) Trusteer reported that the worm had gone financial by trying to compromise banks and other corporate networks.
The URL used is fairly simple so always be sure to go to Facebook from your bookmarks and login, never follow a link from email or sites you do not trust. The assumption here is that the worm is being used to send out malicious links. I have spotted at least one new one today; most of you know when you see them. Sucularts assumption is that hackers are trying to modify this worm from the old email scams to social networking. We suspect it wont be the first by a longshot.
Seculert has provided Facebook with all of the stolen credentials that were found on the Ramnit servers.
Comments