logo

Facebook ads push new Ov3r_Stealer password-stealing malware

ID: 8c40fb74-9eed-50d9-bf16-d628d1d6f79f

STIX ID: report--8c40fb74-9eed-50d9-bf16-d628d1d6f79f

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2024-02-07

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Ov3r_Stealer is a credential- and crypto-stealing malware spread through fake Facebook job ads that redirect victims to Discord-hosted payloads; it employs multiple delivery techniques (CPL/PowerShell, HTML/LNK/SVG smuggling), DLL sideloading, scheduled-task persistence, and exfiltrates harvested credentials, files, and geolocation to a Telegram bot, posing a significant risk to users and organizations handling digital assets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.