This new malware is going after Facebook Business accounts
A new malware strain has been identified targeting Facebook business accounts and stealing their cryptocurrency, experts have revealed.
A new report from Unit 42, the cybersecurity arm of Palo Alto Networks has identified the malware as NodeStealer, a Python variant of the malware originally written in JavaScript.
To get people to install NodeStealer, hackers were reaching out via Facebook, offering fake “professional” budget tracking Microsoft Excel and Google Sheets templates. Given that the attackers were going after business accounts, it’s no wonder that they were trying to lure people in by offering business-related tools and assistance.
Idle campaign
The “templates” were hosted on Google Drive, residing in a .ZIP archive. The archive carried the NodeStealer executable which was also capable of deploying additional malware, such as BitRAT and XWorm, as well as disabling Microsoft Defender antivirus and stealing cryptocurrencies through the MetaMask browser addon wallet.
The strain was used in a malicious campaign that started in December 2022, the researchers said, adding that it’s unlikely that the scheme is still ongoing.
NodeStealer was first spotted in May 2023 by Meta, when the company described it as a stealer that grabs cookies and passwords stored in browsers. NodeStealer was capable of compromising not just Facebook accounts, but Gmail and Outlook, too.
“NodeStealer poses great risk for both individuals and organizations,” Unit 42 researcher Lior Rochberger said. “Besides the direct impact on Facebook business accounts, which is mainly financial, the malware also steals credentials from browsers, which can be used for further attacks.”
Originally, the attackers were using Facebook business accounts to run malicious advertising campaigns on the platform, and lure the social network’s users to third-party websites where they’d incentivize them to download malware or otherwise share sensitive information.
A new malware strain has been identified targeting Facebook business accounts and stealing their cryptocurrency, experts have revealed. A new report from Unit 42, the cybersecurity arm of Palo Alto Networks has identified the malware as NodeStealer, a Python variant of the malware originally written in JavaScript. To get people…
Recent Posts
- This chunky little tablet got my kid to clean up his toys
- OpenAI will let the US government review its AI models before release
- Seagate FireCuda X Vault review: Large capacity and decent transfer rates make this external hard drive a great solution for video and photography
- I customized a MacBook Neo with colorful spare parts
- EveryPlate Meal Kit Review (2026): Low Cost, Simplicity, Flavor
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023