logo

Taiwanese Facebook Biz Pages Fall to Infostealer Phishing Campaign

ID: dd06e707-c119-5908-b3b1-3a9b880b1404

STIX ID: report--dd06e707-c119-5908-b3b1-3a9b880b1404

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-10-31

Date Updated: 2026-04-21

Author: Dark Reading Staff

...
...

Cisco Talos observed a phishing campaign active since at least July targeting Facebook businesses and advertising account users in Taiwan: attackers send decoy emails (impersonating legal teams and known merchants) claiming copyright infringement to coerce victims into downloading malware. The campaign deploys information stealers (Lumma Stealer, Rhadamanthys) embedded in legitimate binaries and uses evasion techniques—shellcode encryption and code obfuscation—to bypass antivirus and sandbox analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.