'Ov3r_Stealer' Malware Spreads Through Facebook to Steal Crates of Info
ID: 2a520807-8f37-5870-841c-a3b60cc032ff
STIX ID: report--2a520807-8f37-5870-841c-a3b60cc032ff
Feed Name: Dark Reading
Date Published: 2024-02-08
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Trustwave SpiderLabs identified a novel infostealer named Ov3r_Stealer being propagated through Facebook job ads, fake accounts and weaponized links that lead to Discord/GitHub-hosted payloads; the malware exfiltrates credentials, cookies, crypto wallets, documents, system and AV info to a Telegram channel. Researchers observed multiple loaders and execution techniques — CPL-based PowerShell, HTML smuggling, SVG/WinRAR exploitation, and malicious LNK shortcuts — a three-file nested payload (WerFaultSecure.exe -> Wer.dll -> Secure.pdf), scheduled-task persistence, and actor aliases/forums tied to distribution and data handling; IoCs and mitigation recommendations are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
