Facebook business owners targeted by hackers
A new cybercrime group has been identified by Malwarebytes to be targeting business owners who use Facebook’s advertising tools.
In a report from the company, Senior Threat Researcher Jérôme Segura noted, “there’s been a resurgence in sponsored posts and accounts that impersonate Meta/Facebook’s own Ads Manager” promising better ad performance.
The attack, which leads victims to install a malicious Chrome browser extension, looks to have generated more than $180,000 in compromised ad budget to date.
Fake Facebook ad generator
Malicious accounts redirect unsuspecting victims to external phishing domains, which use legitimate branding and favicons to trick users into thinking they are still on the Facebook platform.
Among the malicious downloads is a Chrome extension, which uses a Google Translate icon despite its promise to generate better Facebook ad returns. Segura says:
“A quick look at its source code reveals immediate hex obfuscation in an attempt to hide what it is actually doing.”
Reverse engineering found that the extension indeed has nothing to do with Google Translate, and instead focuses on grabbing Facebook login information.
Malwarebytes has discovered more than 20 similar campaigns, one of which goes on to accidentally leak its own stolen data and, subsequently, Google account information, which has since been passed on to Meta by the researchers.
All in, it looks like more than 800 victims have been taken advantage of worldwide, with around two in five coming from the US. The information, which has been shared with Meta, indicates that the threat actors are from Vietnam and are largely targeting Facebook business accounts.
Malwarebytes suggests that Business Manager accounts should regularly be checked for unknown users. Periodically running malware scans also serves as a valuable exercise that could prevent data and money theft.
A new cybercrime group has been identified by Malwarebytes to be targeting business owners who use Facebook’s advertising tools. In a report from the company, Senior Threat Researcher Jérôme Segura noted, “there’s been a resurgence in sponsored posts and accounts that impersonate Meta/Facebook’s own Ads Manager” promising better ad performance.…
Recent Posts
- Samsung Galaxy Book6 Enterprise Edition review: Beautifully engineered business laptop but at this price, I expected better ports than USB 3.2 Gen 2
- Meta made its own AI-generated clickbait news feed
- Kabuto Park captures the fleeting joy of summer vacation
- Control Resonant’s take on New York feels like the Backrooms
- Here comes new Siri again
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023