Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

August 18th, 2010, 13:17 GMT · By

DIY Trojan Kit Targets Facebook Credentials and a Lot More

SHARE:

Adjust text size:


Facebook Hacker generates a password stealing trojan
Enlarge picture
Security researchers have identified a new do-it-yourself kit designed to generate customized trojans that steal Facebook login details, passwords stored inside browsers and even VPN credentials.

The kit is called "Facebook Hacker" and according to security researchers from BitDefender, it is "extremely easy to configure, just like any do-it yourself hack tool designed with the 'skiddie' [script kiddie] in mind."

The program's interface allows the attacker to input the login and SMTP details for the e-mail account where stolen information will be sent by the generated trojan.

Facebook Hacker malware kit interface
Enlarge picture
There are predefined settings for Gmail and Hotmail, as well as the option to modify the default file name or have the trojan display a fake message.

The kit might be simple to use, but the generated malware has a high enough level of sophistication.

It features a hardcoded list of anti-virus and network monitoring products which are blocked or terminated if found running on the victim's computer.

Even though the program is touted as a Facebook hacking tool, the trojan is capable of stealing much more than just login details for the social networking website.

In fact, since it can collect all usernames and passwords stored within any of the major browsers, we could argue that Facebook credentials are the least of concerns.

Information stolen by Facebook Hacker trojan
Enlarge picture
Screenshots of the captured data released by BitDefender show email login credentials lifted from Firefox's signons.sqlite file, however, they could just as well have been for online banking or other sensitive accounts.

And there are also other implications stemming from the fact that a lot of people reuse passwords or don't delete sign-up email notifications containing login information for other services.

"To add insult to injury, the application also enumerates all dialup/VPN entries on the computer and displays their logon details: User Name, Password, and Domain," BitDefender's Loredana Botezatu, notes.

It's worth mentioning that the trojan executable uses the icon of the "Call of Duty: World at War" game and lists Game Adventure Inc. as publisher. BitDefender detects the threat under a generic signature as Trojan.Generic.3576478.

TELL US WHAT YOU THINK:

2,066 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Phishing Kit Steals from Hackers Who Use It

Low-Priced Twitter Spam Kit Sold on Underground Forums

New Crimeware Toolkit Threatens Zeus

DIY Twitter-Controlled Botnet Kit Spotted in the Wild

ZeuS Crimeware Toolkit Features Sophisticated Piracy Protection

READER COMMENTS:


Comment #1 by: rodzilla on 20 Aug 2010, 01:48 UTC reply to this comment

"a new do-it-yourself kit" ?

ROFL

Facebook Hacker is ancient history!

It's still online, with the creation date of 03 May 2010 displayed for all to see.

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM