New malware tricks Facebook users
A new configuration of the Ice IX malware attempts to trick its victims into exposing their credit card details when they try to access their Facebook accounts, PCWorld reported, citing the security firm Trusteer.
The new Ice IX variant displays a Web form inside a browser pop-up window when users log into Facebook. The pop-up is designed to appear as if it's part of the social networking website and asks users for their name, billing address, credit or debit card number, card expiry date and card identification number.
"The attackers claim the information is needed to verify the victim's identity and provide additional security for their Facebook account," Trusteer's chief technology officer, Amit Klein, said in a blog post on Tuesday.
Once the rogue form is submitted, the malware forwards the sensitive information to its authors via an instant messaging protocol, so they can abuse it as soon as possible.
The injection of rogue forms into legitimate online banking websites as they are displayed inside various browsers is a common feature of so-called banking Trojan horses like Ice IX, ZeuS or SpyEye.









