logo

Inside Bitdefender Labs’ Investigation of a Malicious Facebook Ad Campaign Targeting Bitwarden Users

ID: 34e28cd4-3fba-5bcb-a3ef-c6669147bb42

STIX ID: report--34e28cd4-3fba-5bcb-a3ef-c6669147bb42

Feed Name: Bitdefender Labs

Threat Score
70/100

Date Published: 2024-11-18

Date Updated: 2026-04-27

Author: Andrei ANTON-AANEI

...
...

Bitdefender Labs reports an active 2024 malvertising campaign using Facebook ads to impersonate Bitwarden and lure users to sideload a malicious Chrome extension that harvests Facebook cookies, ad account and billing data, IP/geolocation, and other sensitive information, then exfiltrates it to a Google Script C2; the campaign leverages redirect chains, fake Chrome Web Store pages, and manual sideloading to bypass protections and has served ads to thousands of users in Europe with potential to scale globally.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.