Audio By Carbonatix
A computer worm has stolen 45,000 login credentials from Facebook, security experts have warned.
The data is believed to have been taken largely from Facebook accounts in the UK and France, according to security firm Seculert.
The culprit is a well-known piece of malware - dubbed Ramnit - which has been around since April 2010 and has previously stolen banking details.
Facebook told the BBC that it was looking into the issue.
The latest iteration of the worm was discovered in Seculert's labs.
"We suspect that the attackers behind Ramnit are using the stolen credentials to login to victims' Facebook accounts and to transmit malicious links to their friends, thereby magnifying the malware's spread even further," said the researchers on the firm's blog.
"In addition, cybercriminals are taking advantage of the fact that users tend to use the same password in various web-based services to gain remote access to corporate networks," it added.
'Viral power'
Social networks offer rich pickings for hackers because of the huge amount of personal data that is stored on them. Increasingly malware is being updated for the social networking age.
"It appears that sophisticated hackers are now experimenting with replacing the old-school email worms with more up-to-date social network worms. As demonstrated by the 45,000 compromised Facebook subscribers, the viral power of social networks can be manipulated to cause considerable damage to individuals and institutions when it is in the wrong hands," said Seculert.
According to Seculert, 800,000 machines were infected with Ramnit from September to the end of December 2011.
Microsoft's Malware Protection Center (MMPC) described Ramnit as "a multi-component malware family which infects Windows executable as well as HTML files... stealing sensitive information such as stored FTP credentials and browser cookies".
In July 2011 a Symantec report estimated that Ramnit worm variants accounted for 17.3% of all new malicious software infections.
For Facebook users concerned that they have been affected by the worm, the advice is to run anti-virus software.
"It won't necessarily be obvious that you have been attacked. The worm is stealing passwords so it is not going to announce itself," said Graham Cluley, senior security consultant at Sophos.
Update - Friday 6 January, 10:22am: Facebook has responded to this article with the following statement:
"Last week we received from external security researchers a set of user credentials that had been harvested by a piece of malware. Our security experts have reviewed the data, and while the majority of the information was out-of-date, we have initiated remedial steps for all affected users to ensure the security of their accounts.
"Thus far, we have not seen the virus propagating on Facebook itself, but have begun working with our external partners to add protections to our anti-virus systems to help users secure their devices. People can protect themselves by never clicking on strange links and reporting any suspicious activity they encounter on Facebook.
"We encourage our users to become fans of the Facebook Security Page for additional security information."
DISCLAIMER: The Views, Comments, Opinions, Contributions and Statements made by Readers and Contributors on this platform do not necessarily represent the views or policy of Multimedia Group Limited.
Tags:
DISCLAIMER: The Views, Comments, Opinions, Contributions and Statements made by Readers and Contributors on this platform do not necessarily represent the views or policy of Multimedia Group Limited.
Latest Stories
-
Mahama avoiding expensive jet rentals by using brother’s aircraft – Gov’t
1 hour -
All service contracts at Accra International Airport to be held to high delivery standards -Transport Minister warns
2 hours -
Frequent breakdown of presidential jet forced interim use of brother’s aircraft – Felix Ofosu Kwakye
2 hours -
Mother calls for thorough probe into daughter’s death at AdawsoÂ
2 hours -
World Bank Group MD to visit Ghana and Liberia
2 hours -
Automated Road Traffic Law set for passage by end of March
2 hours -
Ghana to use automated technology to catch traffic offenders in real-time
2 hours -
Two robbery suspects killed as police dismantle gang on Obuasi–Dunkwa highway
2 hours -
Mahama’s use of brother’s jet not permanent, it’s due to lack of reliable state aircraft – Felix Ofosu Kwakye
3 hours -
GACL terminates Fixed Base Operation agreement with McDan Aviation over persistent debt
3 hours -
‘What exactly is the problem if Mahama uses his brother’s jet?’ – Kwakye Ofosu asks critics
3 hours -
I’ll be surprised if Ghanaians think Mahama using his brother’s jet comes at no cost to the state – Asafo-Adjei
4 hours -
PassionAir announces Kumasi route disruptions, apologises to passengers
4 hours -
Police dismantle armed robbery gang on Obuasi–Dunkwa highway
4 hours -
Ghana could face security risks amid international intelligence cooperation – Bosome Freho MP warns
4 hours
