Researchers spotted a new cookie-stealing Trojan called Cookiethief that is targeting users social media accounts and browsers. Kaspersky Lab observed that the primary aim of the malware was to gain root privileges on a victims Android device. The malware leveraged that level of access to transfer cookies employed by the user’s browser and Facebook account to a command-and-control (C&C) server. It did so not by exploiting a vulnerability in either Facebook or browser. Instead, it connected with a backdoor installed on the same device and used it to execute commands.”]

