Ramnit worm steals 31,000 UK Facebook logins

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS

Hackers have used a Ramnit worm variant to harvest 31,000 Facebook usernames and passwords from British users, but most of the stolen information is out of date, according to the social-networking company.

Ramnit infection chart

Hackers have used a Ramnit worm variant to harvest 31,000 Facebook usernames and passwords from British users. Image credit: Seculert

Threat assessment company Seculert said on Thursday that the financial fraud Trojan Ramnit, which has existed in one form or another since at least April 2010, has now "gone social" and is using Facebook to spread. According to Seculert's analysis, around 69 percent of those targeted were in the UK and 27 percent in France.

"Recently, our research lab identified a completely new 'financial' Ramnit variant aimed at stealing Facebook login credentials," Seculert said. "Since the Ramnit Facebook [command and control server] URL is visible and accessible it was fairly straightforward to detect that over 45,000 Facebook login credentials have been stolen worldwide, mostly from users in the United Kingdom and France."

It appears that sophisticated hackers are now experimenting with replacing the old-school email worms with more up-to-date social network worms.

– Seculert

Ramnit is three-component malware that can infect Windows executable files, Microsoft Office and HTML files, using the latter to replicate itself, according to Microsoft and McAfee. In August, the worm became a tool for perpetrating financial fraud, after malware writers linked it up with leaked Zeus Trojan source code. Seculert, which said it detected Ramnit on 800,000 computers in the final three months of 2011, described the shift to Facebook as a new "twist".

"With the recent Zeus Facebook worm and this latest Ramnit variant, it appears that sophisticated hackers are now experimenting with replacing the old-school email worms with more up-to-date social network worms," Seculert said.

"We suspect that the attackers behind Ramnit are using the stolen credentials to log into victims' Facebook accounts and to transmit malicious links to their friends, thereby magnifying the malware's spread even further," it said. "In addition, cybercriminals are taking advantage of the fact that users tend to use the same password in various web-based services (Facebook, Gmail, Corporate SSL VPN, Outlook Web Access, etc) to gain remote access to corporate networks."

Data 'out of date'

Seculert sent Facebook the harvested data it had found last week. On Thursday, the social-networking company acknowledged that user login credentials had been collected, but said most of them are invalid.

"Our security experts have reviewed the data, and while the majority of the information was out of date, we have initiated remedial steps for all affected users to ensure the security of their accounts," Facebook said

Speaking to ZDNet UK, a spokesman for the social-networking company refused to be drawn on how many user logins constituted a "majority". He did give more details on the remedial steps being taken, saying these involve putting people affected into a security "roadblock".

"Account activity is locked down until they pass through this roadblock, where they must reset their password," the spokesman said.

Facebook also said it had detected no evidence of Ramnit spreading via its site.

"Thus far, we have not seen the virus propagating on Facebook itself, but have begun working with our external partners to add protections to our antivirus systems to help users secure their devices," it said.


Get the latest technology news and analysis, blogs and reviews delivered directly to your inbox with ZDNet UK's newsletters.

Talkback

who on earth is sad enough to steal facebook logins? if anyone actually cares that their login has been stolen then they deserve it. social networking was supposed to be fun at first, now people depend on it. its rediculous, no I dont have facebook and I still have contact with my friends that matter

qazwsxedcrfvtgby 6 January, 2012 16:14
Reply

Hackers have used a Ramnit worm variant to harvest 31,000 Facebook usernames and passwords from British users.
Update your Anti Virus Now.

David Burton via Facebook 7 January, 2012 11:06
Reply

@ qazwsxedcrfvtgby . I find it disturbing that you can be so short sighted. How many of your passwords, pin numbers and user names have nothing to do with your life experiences. Identity theft is a major crime because of the financial and employment repurcussions that can occur. Stealign log-in credentials is not the main aim of such a virus, access to sensitive information that msot consider to be 'safe' is incredibly serious. Access to adresses, family details, medical issues to name a few. Think before condemning even if on the surface your argument seems to make sense.

Chris Miller via Facebook 7 January, 2012 17:41
Reply

Lol they're more than welcome to my Facebook, have fun looking at the loads of mindless junk on it, just like every other facebook account.

Mombasa69 7 January, 2012 18:57
Reply

It scared that facebook account would be hacked, there are no of hacking companies are hacked facebook active accounts. Mostly its due to IPs details. We should try Secure Ip to connect our facebook account. its only due to VPN software.

UK VPN 23 January, 2012 14:04
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

dede0202

Hello ALL USERS OF THE PIRATE BAY I WOULD PUT AN EXPLANATION ON PIRACY Story Idea ILLIGALE AND SHARING THOSE THAT NET Dissent NOT WELL BUT TO CA...

5 hours ago by dede0202 on The Pirate Bay infringes copyright, High Court decides
Sungwoo

do You know that? it can install 4G Ram. So i buy 4g and install It work! I can run call of duty 4,6,7 [Modern war... 1,2,3] Call of duty 1 was...

5 hours ago by Sungwoo on Loose Ends - Upgrading the Aspire One 522
itsajob

2. Bad idea. Making up patch cables loses you your commission from the cable supplier. 3. If you tidy up, other people can understand where the...

11 hours ago by itsajob on Ten IT jobs to save up for those rare lulls
Roberto_Store

Now On Sale, Unlocked iPhone 4S / Galaxy Note In Factory Box. Roberto-Techie(UK) ”Now on Sales” Smartphone, Android,Tablets,Gadget &...

15 hours ago by Roberto_Store on Samsung Galaxy S III lined up for sale
Paul Smyth

Is this classic FUD? One thing I would definitely have notice is a Mozilla threat to stop supporting GNU/Linux.

17 hours ago by Paul Smyth via Facebook on Firefox rapid release improves Fedora Linux
UnderINK

I agree with the previous commenter wholeheartedly. I couldn't say it better myself. This is very 'Big Brother'. And while I agree with protecting...

21 hours ago by UnderINK on European e-identity plan to be unveiled this month
Simon Bisson and Mary Branscombe

Nice to see that Turing's idea of a general purpose computer doing once-hardware-powered tasks in software is now universal ;-) Mary

1 day ago by Simon Bisson and Mary Branscombe on Software with everything
Jason Burchell

seriously now. I've only bothered to read a small bit of the comments. do me and the rest of the world a favour. stop saying it does not work or...

1 day ago by Jason Burchell via Facebook on Music industry negotiating over 24-bit downloads
Philip Charles Cohen

Read about it and weep, John Donahoe ... In addition to Visa’s V.me, there is now MasterCard’s PayPass digital wallet soon to arrive; another...

1 day ago by Philip Charles Cohen via Facebook on PayPal takes phone-based payments to the high street
apexwm

Leslie Satenstein : Where have you ever seen Mozilla even mention this? Firefox is the most popular browser in the GNU/Linux OS, so I don't see...

1 day ago by apexwm on Firefox rapid release improves Fedora Linux
songmaster

SHleG: Do you remember building a clockwork scorpion kit (I'm pretty sure I have a photo of it somewhere) — I think it was called something like...

2 days ago by songmaster on Software with everything
Chris Wortman

Good I love Yahoo! Their search engine is getting better than Google as of late. I find more of what I want on the first page, and usually within...

2 days ago by Chris Wortman via Facebook on Linux Mint 13 ramps up for KDE release
PatrickG

openhgs has made the point for Windows 8 multiple monitors without realising it! With Windows 7 you have to switch the mouse and so your focus...

2 days ago by PatrickG on Windows 8 could speed multi-monitor uptake
Leslie Satenstein

Mozilla has threatened to stop supporting Linux. I guess that UBUNTU is going with another browser. I indicated that if Mozilla stops supporting...

2 days ago by Leslie Satenstein via Facebook on Firefox rapid release improves Fedora Linux
Andy Bolstridge

Much as I abhor Microsoft's licensing practices, this is almost certainly down to purchasing IT equipment via 3rd party consultants - you get the...

2 days ago by Andy Bolstridge via Facebook on 6 million wasted licences and £1,200 PCs: welcome to government IT
Jack Schofield

@openhgs Windows users have had multiple desktops since Linus started writing Linux. They just haven't shipped as standard because not enough...

2 days ago by Jack Schofield on Windows 8 could speed multi-monitor uptake
Jack Schofield

@Phil at Cloud4 What, Microsoft gets £1,200 per PC and £1,622 per server? Gosh, I'm amazed....

2 days ago by Jack Schofield on 6 million wasted licences and £1,200 PCs: welcome to government IT
craigsc

You guys have no idea what is going on at Autonomy. Autonomy could have been a much more profitable organization. The sales operations at Autonomy...

2 days ago by craigsc on HP cuts 27,000 staff as Autonomy chief Lynch leaves
Moley

How does this impact on dual or multi booting? Seems to me to more or less prohibit this, from Windows 8 anyway. Will Grub 2 recognise Windows 8,...

2 days ago by Moley on Windows 8 start-up speed forces USB boot workaround
apexwm

I don't understand why there cannot be a slight pause during the boot process so the user can press a key. Many operating systems do this, even if...

3 days ago by apexwm on Windows 8 start-up speed forces USB boot workaround