logo

Unmasking the SYS01 Infostealer Threat: Bitdefender Labs Tracks Global Malvertising Campaign Targeting Meta Business Pages

ID: be0c86f2-c794-541c-b0c2-88a665f147a9

STIX ID: report--be0c86f2-c794-541c-b0c2-88a665f147a9

Feed Name: Bitdefender Labs

Threat Score
78/100

Date Published: 2024-10-30

Date Updated: 2026-04-27

Author: Ionut Alexandru BALTARIU

...
...

Bitdefender Labs reports an active, global malvertising campaign leveraging Meta ads to distribute the SYS01 InfoStealer via malicious Electron applications and password-protected archives; the malware uses obfuscated JavaScript, PowerShell and IonCube-encoded PHP for persistence and C2 communications, targets Facebook Business accounts to scale ad distribution, employs sandbox detection and rapid code updates for evasion, and is linked to dozens of malicious hosting and C2 domains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.