Security News > 2021 > August > FlyTrap malware hijacks thousands of Facebook accounts

FlyTrap malware hijacks thousands of Facebook accounts
2021-08-09 21:43

A new Android threat that researchers call FlyTrap has been hijacking Facebook accounts of users in more than 140 countries by stealing session cookies.

FlyTrap campaigns rely on simple social engineering tactics to trick victims into using their Facebook credentials to log into malicious apps that collected data associated with the social media session.

Researchers at mobile security company Zimperium detected the new piece of malware and found that the stolen information was accessible to anyone who discovered FlyTrap's command and control server.

FlyTrap campaigns have been running since at least March.

"Just like any user manipulation, the high-quality graphics and official-looking login screens are common tactics to have users take action that could reveal sensitive information. In this case, while the user is logging into their official account, the FlyTrap Trojan is hijacking the session information for malicious intent" - Aazim Yaswant, Android malware researcher, Zimperium.

Despite not using a new technique, FlyTrap managed to hijack a significant number of Facebook accounts.


News URL

https://www.bleepingcomputer.com/news/security/flytrap-malware-hijacks-thousands-of-facebook-accounts/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Facebook 30 2 44 52 19 117