logo

'Ov3r_Stealer' Malware Spreads Through Facebook to Steal Crates of Info

ID: 2a520807-8f37-5870-841c-a3b60cc032ff

STIX ID: report--2a520807-8f37-5870-841c-a3b60cc032ff

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-02-08

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Trustwave SpiderLabs identified a novel infostealer named Ov3r_Stealer being propagated through Facebook job ads, fake accounts and weaponized links that lead to Discord/GitHub-hosted payloads; the malware exfiltrates credentials, cookies, crypto wallets, documents, system and AV info to a Telegram channel. Researchers observed multiple loaders and execution techniques — CPL-based PowerShell, HTML smuggling, SVG/WinRAR exploitation, and malicious LNK shortcuts — a three-file nested payload (WerFaultSecure.exe -> Wer.dll -> Secure.pdf), scheduled-task persistence, and actor aliases/forums tied to distribution and data handling; IoCs and mitigation recommendations are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.