logo

Inside Bitdefender Labs’ Investigation of a Malicious Facebook Ad Campaign Targeting Bitwarden Users

ID: af4de0cb-e56e-5ac2-a82f-895ee0e87859

STIX ID: report--af4de0cb-e56e-5ac2-a82f-895ee0e87859

Feed Name: Bitdefender Labs

Threat Score
70/100

Date Published: 2024-11-18

Date Updated: 2026-04-27

Author: Andrei ANTON-AANEI

...
...

Bitdefender Labs details a malvertising campaign on Facebook that impersonates Bitwarden to coax users into sideloading a malicious Chrome extension (distributed via Google Drive). The extension requests extensive permissions, harvests Facebook cookies, business/ad account and billing details, collects IP/geolocation data, and exfiltrates information to a Google Script C2; thousands of users have been served and the campaign has potential to scale globally. The report includes manifest and script artifacts, attack steps, detection ideas, and user mitigation advice.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.