logo

Weaponizing Facebook Ads: Inside the Multi-Stage Malware Campaign Exploiting Cryptocurrency Brands

ID: 4bd55e8d-c63b-5906-8615-cc6c4adb6d57

STIX ID: report--4bd55e8d-c63b-5906-8615-cc6c4adb6d57

Feed Name: Bitdefender Labs

Threat Score
75/100

Date Published: 2025-05-08

Date Updated: 2026-04-27

Author: Ionut Alexandru BALTARIU

...
...

This Bitdefender analysis details an ongoing, large-scale malvertising campaign on Facebook that impersonates well-known cryptocurrency platforms and influencers to trick users into downloading a malicious "installer.msi". The campaign uses advanced evasion and targeting (ad query parameters, browser checks, demographic filters), coordinates front-end scripts with a localhost .NET server (msedge_proxy.exe) to run WMI queries and schedule tasks, and delivers evolving payloads via PowerShell and C2 servers for data exfiltration and secondary payload deployment; Bitdefender detected related DLLs and JavaScript and provides IoCs to partners.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.