logo

Cybercriminals Exploit Facebook Ads to Launch Sophisticated Multi-Stage Malware Campaigns

ID: b10bc62e-8336-58fc-b070-e37d2086c8b9

STIX ID: report--b10bc62e-8336-58fc-b070-e37d2086c8b9

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2025-05-09

Date Updated: 2026-05-05

Author: Mandvi

...
...

A persistent malvertising campaign on Facebook impersonates major cryptocurrency platforms to distribute a disguised "installer.msi" that establishes a local .NET command server (commonly on ports 30308/30303), uses SharedWorker and PowerShell for payload execution and persistence, performs WMI-based fingerprinting and data exfiltration, and leverages Facebook targeting and sandbox-detection checks to deliver malicious payloads at scale across hundreds of accounts and thousands of ads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.