Facebook ads for Windows desktop themes push info-stealing malware
ID: 500379cc-5c9e-52a6-b4e5-0974aed6ceb3
STIX ID: report--500379cc-5c9e-52a6-b4e5-0974aed6ceb3
Feed Name: Bleeping Computer
Trustwave observed a large-scale malvertising campaign that uses Facebook business pages (including hijacked pages) and paid ads to promote fake Windows themes, game/software downloads, and AI tools that deliver the SYS01 information-stealing malware. The delivered ZIPs contain executables that perform DLL sideloading and launch PowerShell and PHP components to evade detection, create persistence, and exfiltrate browser cookies, saved credentials, crypto wallets and Facebook advertising/account data — which attackers can sell or use to expand further malvertising and account hijacking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
