Security News > 2020 > March > 'Cookiethief' Android Malware Hijacks Facebook Accounts

'Cookiethief' Android Malware Hijacks Facebook Accounts
2020-03-13 12:50

A recently discovered Android Trojan was designed to gain root access on infected devices and hijack Facebook accounts by stealing cookies from the browser and the social media app.

While it's uncertain how the Trojan infects devices - it does not exploit flaws in the Facebook application or the browser - it achieves root by connecting with another backdoor installed on the smartphone, and passes it a shell command.

The C&C server addresses and employed encryption keys show connections between Cookiethief and Trojans such as Sivu, Triada, and Ztorg.

Such malware is often pre-installed on devices, or is installed via operating system vulnerabilities.

"As a result, a persistent backdoor like Bood, along with the auxiliary programs Cookiethief and Youzicheng, can end up on the device," Kaspersky concludes.


News URL

http://feedproxy.google.com/~r/Securityweek/~3/Xea3aFXjOg0/cookiethief-android-malware-hijacks-facebook-accounts

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Facebook 30 2 44 52 19 117
Android 4 0 17 2 0 19