logo

Beware: Fake Facebook Job Ads Spreading 'Ov3r_Stealer' to Steal Crypto and Credentials

ID: 131abf90-df8d-56e9-a17b-9ebbef640215

STIX ID: report--131abf90-df8d-56e9-a17b-9ebbef640215

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-02-06

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Trustwave SpiderLabs observed a social‑engineering campaign leveraging fake Facebook job ads and a weaponized PDF that leads victims to download a .URL shortcut which drops a .CPL executed via control.exe to launch a PowerShell loader from GitHub, ultimately deploying a Windows infostealer named Ov3r_Stealer. Ov3r_Stealer harvests IP/location, hardware info, passwords, cookies, credit card data, auto‑fills, browser extensions, crypto wallets, Office documents and AV lists, exfiltrating data to a Telegram channel; it shares code with the Phemedrone stealer and may be reused as a loader for additional payloads or sold as MaaS.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.