logo

Malvertising Campaign on Meta Expands to Android, Pushing Advanced Crypto-Stealing Malware to Users Worldwide

ID: 315f90b2-c096-5210-81eb-c03c623c4f29

STIX ID: report--315f90b2-c096-5210-81eb-c03c623c4f29

Feed Name: Bitdefender Labs

Threat Score
80/100

Date Published: 2025-08-26

Date Updated: 2026-04-27

Author: Ionut Alexandru BALTARIU

...
...

Bitdefender Labs uncovered an active malvertising campaign using Facebook/Meta ads impersonating TradingView and other brands to distribute an evolved Brokewell Android trojan via sideloaded APKs; the malware requests powerful permissions (accessibility, lock-screen PIN), communicates over Tor/WSS, and supports extensive capabilities including crypto theft, 2FA scraping/export, SMS interception, keylogging, camera/mic access, remote control and self-destruct — tens of thousands of users in the EU were reached and multiple IOCs and hashes are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.