Cybercriminals Exploit Facebook Ads to Launch Sophisticated Multi-Stage Malware Campaigns
ID: b10bc62e-8336-58fc-b070-e37d2086c8b9
STIX ID: report--b10bc62e-8336-58fc-b070-e37d2086c8b9
Feed Name: Cyber Press
A persistent malvertising campaign on Facebook impersonates major cryptocurrency platforms to distribute a disguised "installer.msi" that establishes a local .NET command server (commonly on ports 30308/30303), uses SharedWorker and PowerShell for payload execution and persistence, performs WMI-based fingerprinting and data exfiltration, and leverages Facebook targeting and sandbox-detection checks to deliver malicious payloads at scale across hundreds of accounts and thousands of ads.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
