logo

Unmasking the SYS01 Infostealer Threat: Bitdefender Labs Tracks Global Malvertising Campaign Targeting Meta Business Pages

ID: 2601fc5e-b790-5af9-999e-56cc700a0bbf

STIX ID: report--2601fc5e-b790-5af9-999e-56cc700a0bbf

Feed Name: Bitdefender Labs

Threat Score
78/100

Date Published: 2024-10-30

Date Updated: 2026-04-27

Author: Ionut Alexandru BALTARIU

...
...

Bitdefender Labs describes an active, global malvertising campaign (SYS01) that uses Meta ads to distribute an ElectronJS-packaged infostealer. The attackers impersonate popular brands and software, host downloads on file-sharing sites, leverage nearly a hundred malicious domains and dynamic C2s (including Telegram-based discovery), employ sandbox-evasion and obfuscation, persist via scheduled tasks, and monetize by hijacking Facebook Business accounts to scale ad distribution and sell stolen credentials. The report includes sample IOCs and actionable protections such as using official sources, enabling 2FA, and employing updated security solutions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.