logo

Ongoing FileFix Attack Installs StealC Infostealer Via Fake Facebook Pages

ID: 55e58044-b63c-596a-b657-8f45e200e637

STIX ID: report--55e58044-b63c-596a-b657-8f45e200e637

Feed Name: HackRead

Threat Score
70/100

Date Published: 2025-09-16

Date Updated: 2026-04-22

Author: Waqas

...
...

Acronis researchers have observed an active FileFix phishing campaign that lures victims with fake Facebook Security pages and a deceptively simple instruction (pasting a path into a file upload address bar) that causes code execution. The infection chain uses images hosted on Bitbucket containing hidden scripts and executables via steganography, and ultimately delivers the StealC infostealer which can harvest credentials, browser data, cryptocurrency wallets, and tokens and may deploy additional malware. Phishing pages are multilingual and obfuscated, with submissions reported from multiple countries; defenders are advised to avoid running untrusted scripts and adopt breach-resilient controls such as Zero Trust.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.