FFDroider Stealer Is Targeting Social Media Platform
ID: 685ef6a0-0724-54c5-9daf-581ccc9a78cc
STIX ID: report--685ef6a0-0724-54c5-9daf-581ccc9a78cc
Feed Name: Zscaler Security Research Blog
Zscaler ThreatLabz analyzed a Windows info-stealer named Win32.PWS.FFDroider (FFDroider) distributed via cracked installers and malicious URLs; it harvests cookies and saved credentials from Chrome, Firefox, IE/Edge, replays Facebook/Instagram sessions to extract account and Ads Manager/payment data, adds persistence and firewall rules, downloads updates from C2, and exfiltrates encrypted JSON payloads to observed command-and-control servers — the report includes technical TTPs, decryption routines, sample hashes and malicious URLs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
