More fake Facebook job ads are spreading malware to steal all your details


Cybersecurity researchers have spotted yet another malicious Facebook ad campaign looking to trick users into installing malware on your Windows device.
The team from Trustwave SpiderLabs revealed how an unnamed threat actor created a Facebook ad campaign for digital advertising jobs.
Those that click on the ad are served a weaponized PDF file with an embedded “Access Document” button. Clicking the button triggers a chain reaction that ultimately delivers an infostealer called Ov3r_Stealer.
Selling data on the dark web
“This malware is designed to steal credentials and crypto wallets and send those to a Telegram channel that the threat actor monitors,” Trustwave SpiderLabs said in its report.
Besides stealing passwords and crypto wallet data, Ov3r_Stealer can also steal IP address-based locations, hardware information, cookies, credit card data, auto-fills, browser extensions, Microsoft Office documents, and a list of antivirus products that the victim has installed on their Windows device.
At this point, the goal of the campaign seems to be data exfiltration, likely to be sold to a third-party at a later date. However, the researchers don’t exclude the possibility of the malware being updated to act as a ransomware encryptor, too.
The campaign appears to have quite a few similarities with another recently discovered campaign that was delivering the Phemedrone Stealer. In both cases, the attackers used the same GitHub repository (nateeintanan252) to pull the loader, and both infostealers share plenty of code.
“This malware has recently been reported, and it may be that Phemedrone was re-purposed and renamed to Ov3r_Stealer,” Trustwave said. “The main difference between the two is that Phemedrone is written in C#.”
The researchers even found a person on Telegram, by the name Liu Kong, claiming to have developed both variants, and stating they were happy with how the tool works in the wild.
More from TechRadar Pro
Cybersecurity researchers have spotted yet another malicious Facebook ad campaign looking to trick users into installing malware on your Windows device. The team from Trustwave SpiderLabs revealed how an unnamed threat actor created a Facebook ad campaign for digital advertising jobs. Those that click on the ad are served a…
Recent Posts
- Everything missing from the iPhone 16e, including MagSafe and Photographic Styles
- Reddit is reportedly experiencing some outages
- Google may be close to launching YouTube Premium Lite
- Someone wants to sell you a digital version of the antiquated typewriter but without a glued-on keyboard (no really)
- Carbon removal is the next big fossil fuel boom, oil company says
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010