logo

FFDroider Stealer Is Targeting Social Media Platform

ID: 685ef6a0-0724-54c5-9daf-581ccc9a78cc

STIX ID: report--685ef6a0-0724-54c5-9daf-581ccc9a78cc

Feed Name: Zscaler Security Research Blog

Threat Score
72/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabz analyzed a Windows info-stealer named Win32.PWS.FFDroider (FFDroider) distributed via cracked installers and malicious URLs; it harvests cookies and saved credentials from Chrome, Firefox, IE/Edge, replays Facebook/Instagram sessions to extract account and Ads Manager/payment data, adds persistence and firewall rules, downloads updates from C2, and exfiltrates encrypted JSON payloads to observed command-and-control servers — the report includes technical TTPs, decryption routines, sample hashes and malicious URLs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.