Don’t click – Facebook users are being targeted with some very NSFW malware attacks
Hackers are using the promise of soft porn content on social media to drop infostealing malware onto unsuspecting victims.
This is according to a new report from Bitdefender, whose researchers recently discovered and analyzed a major operation on Facebook. The goal of the campaign is to steal sensitive personal information, as well as payment and cryptocurrency data.
The researchers estimate roughly 100,000 potential downloads of the malware from the Ad reach analysis. The target cohort is males who are 45 years of age or older.
Enter NodeStealer
Here’s how it works: the attackers create fake Facebook profiles and name them “Album Update”, “Album Girl News Update”, or similar. Then, they post a single blurred photo of a naked woman.
Then they use previously compromised Facebook Business accounts (those with the ability to run Facebook Ad campaigns) to run ad campaigns, promoting those profiles and claiming that new, fully-visible photos, will be uploaded soon. The message also tries to create a sense of urgency, by stating that the pics will probably be deleted soon after being posted.
The gullible victims that end up clicking on the link won’t get the pics, but will rather get an executable file called Photo Album.exe. That file will drop a new version of NodeStealer, a known infostealer malware.
Earlier versions were designed primarily to steal cookie sessions from web browsers and use them to access people’s Facebook accounts. This new version also grants access to email platforms such as Gmail or Outlook, as well as allowing attackers to steal cryptocurrencies from people’s wallets.
The campaign also seems to be quite successful, as a single ad generated as much as 15,000 downloads in the first 24 hours.
If you’re wondering why Facebook doesn’t just remove these ads – it’s probably trying to. However, the attackers are using a maximum of five active ads at a time, and switch between them at a 24-hour interval, thus minimizing the chances of being reported by users.
The best advice to stay safe from these and similar threats is to use common sense when surfing; if something seems like a scam, then it probably is.
More from TechRadar Pro
Hackers are using the promise of soft porn content on social media to drop infostealing malware onto unsuspecting victims. This is according to a new report from Bitdefender, whose researchers recently discovered and analyzed a major operation on Facebook. The goal of the campaign is to steal sensitive personal information, as…
Recent Posts
- WiiM expands its whole-home ecosystem with a new soundbar
- You can make the hyper-violence in Marvel’s Wolverine more PG-13, if you want to
- Best Buy launches a huge Sonos sale ahead of the World Cup — here are the 7 top-rated soundbars and speakers I’d buy
- Nvidia is already planning N2X and N3X chips — the goal is the Star Trek computer
- A British MP is suing to see if xAI is legally responsible for the images Grok produces
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023