Beware! This malware can steal passwords, credit card info
If successful, the attackers would have full access to the victim's exchange account and/or wallet and be able to use those funds as if they were the user themselves.
Global cybersecurity company Palo Alto Networks has discovered a malware that is capable of stealing saved usernames and passwords in Google Chrome, saved credit card credentials in Chrome and iPhones text messages if backed up to a Mac.
The malware named "CookieMiner" is capable of stealing browser cookies associated with mainstream cryptocurrency exchanges and wallet service websites visited by the victims, said Unit 42, an arm of Palo Alto Networks.
It steals saved passwords in Chrome and iPhone text messages from iTunes backups on the tethered Mac.
"By leveraging the combination of stolen login credentials, web cookies and SMS data, based on past attacks like this, we believe the bad actors could bypass multi-factor authentication for these sites," the researchers noted.
If successful, the attackers would have full access to the victim's exchange account and/or wallet and be able to use those funds as if they were the user themselves.
The malware also configures the system to load coinmining software on the system.
Web cookies are widely used for authentication. Once a user logs into a website, its cookies are stored for the web server to know the login status.
If the cookies are stolen, the attacker could potentially sign into the website to use the victim's account.
Watch This Zee Business Tweet Video
#Budget2019 पर सबसे तेज और धमाकेदार कवरेज देखिए #BudgetWithZEE पर | @AnilSinghviZEE https://t.co/dLiybAfvan
— Zee Business (@ZeeBusiness) 1 February 2019
"Stealing cookies is an important step to bypass login anomaly detection. If only the username and password are stolen and used by a bad actor, the website may issue an alert or request additional authentication for a new login," said Unit 42 in a blog post on Thursday.
However, if an authentication cookie is also provided along with the user name and password, the website might believe the session is associated with a previously authenticated system host and not issue an alert or request additional authentication methods.
Get Latest Business News, Stock Market Updates and Videos; Check your tax outgo through Income Tax Calculator and save money through our Personal Finance coverage. Check Business Breaking News Live on Zee Business Twitter and Facebook. Subscribe on YouTube.
RECOMMENDED STORIES
Retirement Planning: SIP+SWP combination; Rs 15,000 monthly SIP for 25 years and then Rs 1,52,000 monthly income for 30 years
Top Gold ETF vs Top Large Cap Mutual Fund 10-year Return Calculator: Which has given higher return on Rs 11 lakh investment; see calculations
Retirement Calculator: 40 years of age, Rs 50,000 monthly expenses; what should be retirement corpus and monthly investment
SBI 444-day FD vs Union Bank of India 333-day FD: Know maturity amount on Rs 4 lakh and Rs 8 lakh investments for general and senior citizens
EPF vs SIP vs PPF Calculator: Rs 12,000 monthly investment for 30 years; which can create highest retirement corpus
Home loan EMI vs Mutual Fund SIP Calculator: Rs 70 lakh home loan EMI for 20 years or SIP equal to EMI for 10 years; which can be easier route to buy home; know maths
12:25 PM IST