Friday, February 21, 2025
HomeCyber Security NewsBeware of Facebook Ads That Deliver Password-Stealing Malware

Beware of Facebook Ads That Deliver Password-Stealing Malware

Published on

SIEM as a Service

Follow Us on Google News

A new malware called Ov3r_Stealer was found to be intended for stealing cryptocurrency wallets and passwords and then sending them to a Telegram channel that the threat actor maintains.

Identified early in December, the malware was spread via a Facebook advertisement for an account manager position. 

The user was directed via weaponized links to a malicious Discord content delivery URL, which triggered the attack’s execution phase.

“The malware is designed to exfiltrate specific types of data such as GeoLocation (based on IP), hardware info, passwords, cookies, credit card information, auto-fills, browser extensions, crypto wallets, Office documents, and antivirus product information,” SpiderLabs shared with Cyber Security News.

Document
Run Free ThreatScan on Your Mailbox

AI-Powered Protection for Business Email Security

Trustifi’s Advanced threat protection prevents the widest spectrum of sophisticated attacks before they reach a user’s mailbox. Try Trustifi Free Threat Scan with Sophisticated AI-Powered Email Protection .

Facebook Ads Delivering Password Stealing Malware

A weaponized PDF file is used for the malware’s first access and transmission. The file impersonates a shared file on OneDrive. A simple clickable OneDrive link was found on a fake Facebook profile purporting to be Amazon CEO Andy Jassy. 

Another instance was seen applying for a Digital Advertising position through a Facebook advertisement.

 Facebook ad for a job in Digital Advertising

Upon selecting the “Access Document” link on the Facebook page, a file ending in .url is downloaded to initiate the subsequent phase. 

SpiderLabs at Trustwave found a quicker way to reach the [.url] in the job notification for “pink women’s magazine” on Facebook by utilizing the PDF file’s information.

The malware was downloaded in three files from a GitHub site utilizing a Powershell script that was run in the victim’s environment and pretended to be Windows Control Panel binary. 

Researchers observed additional ways to install the malware onto the system throughout the malware family study. These methods included HTML smuggling, SVG smuggling, and LNK file masquerading.

After the malware’s three files are loaded and launched on the system, a Scheduled Task is used as a persistence mechanism to make the malware run every ninety minutes.

After the data is acquired, it is exfiltrated to a Telegram channel that the threat actor monitors. All of this data might end up in the hands of the highest bidder, or the malware might modularize and then be used as a dropper for additional malware or post-exploit tools, all the way up to ransomware.

Researchers have found striking similarities between the Phemedrone stealer malware and the Ov3r_Stealer malware.

Given the latest reports of this malware, it’s possible that Phemedrone was repurposed and given the new name Ov3r_Stealer. Phemedrone is written in C#, which is the primary distinction between the two.

The team discovered numerous aliases, communication channels, and repositories during their frantic search for information on the threat actors. Aliases like “Liu Kong,” “MR Meta,” “MeoBlackA,” and “John Macollan” were discovered in forums like “Pwn3rzs Chat,” “Golden Dragon Lounge,” “Data Pro,” and “KGB Forums,” where a regular gathering of “researchers,” threat actors, and inquisitive people takes place.

Mitigation

  • Engage Security Awareness Programs
  • Regular Application and Service audits and baselining
  • Application patching
  • Run continuous Threat Hunting through your environments for undetected compromises.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

SPAWNCHIMERA Malware Exploits Ivanti Buffer Overflow Vulnerability by Applying a Critical Fix

In a recent development, the SPAWNCHIMERA malware family has been identified exploiting the buffer...

Sitevision Auto-Generated Password Vulnerability Lets Hackers Steal Signing Key

A significant vulnerability in Sitevision CMS, versions 10.3.1 and earlier, has been identified, allowing...

NSA Allegedly Hacked Northwestern Polytechnical University, China Claims

Chinese cybersecurity entities have accused the U.S. National Security Agency (NSA) of orchestrating a...

ACRStealer Malware Abuses Google Docs as C2 to Steal Login Credentials

The ACRStealer malware, an infostealer disguised as illegal software such as cracks and keygens,...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

SPAWNCHIMERA Malware Exploits Ivanti Buffer Overflow Vulnerability by Applying a Critical Fix

In a recent development, the SPAWNCHIMERA malware family has been identified exploiting the buffer...

Sitevision Auto-Generated Password Vulnerability Lets Hackers Steal Signing Key

A significant vulnerability in Sitevision CMS, versions 10.3.1 and earlier, has been identified, allowing...

NSA Allegedly Hacked Northwestern Polytechnical University, China Claims

Chinese cybersecurity entities have accused the U.S. National Security Agency (NSA) of orchestrating a...