Hackers pushing fake Bitwarden updates hit thousands of devices with data stealing malware


- Fake facebooks ads are posing as Bitwarden security updates
- The updates actually install a malicious browser extension
- The extensions steals personal and financial data from Facebook
Bitdefender has warned hackers are using the Facebook advertising platform to trick Bitwarden users into installing a fake security update that steals personal data and credit card information from businesses and individuals alike.
The advert lures a user through a string of redirected URLs before landing them at a phishing page designed to mimic the official Chrome Web Store.
Once downloaded, the malware leeches data from Facebook’s Graph API which is then sent to the attacker via a Google Script URL that acts as a command and control (C2) server.
Fake facebook ads spreading malware
The fake adverts create a sense of urgency for users, displaying messages such as “Warning: Your Passwords Are at Risk!” and using Bitwarden branding to appear as a legitimate advert.
Once lured to the fake Chrome Web Store, users then download a zip file that is manually loaded as a Chrome browser extension using Developer mode, avoiding the usual security checks that would take place when adding a browser extension.
The extension then asks for permission to operate on all websites, modify network requests, and access storage and cookies allowing it to collect and exfiltrate the data your browser has access to. Once the extension is opened, the malware looks for the ‘c_user’ cookie on Facebook, which contains the Facebook user ID.
The malware also uses a background.js script to harvest data from Facebook cookies, including information on location and IP address, and uses the Facebook Graph API to extract all of the stolen data to the hackers C2 server.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Bitdefender recommends that users and security teams keep an eye out for extensions that request excessive permissions, as well as those with obfuscated functions such as ‘chrome.runtime.onInstalled.addListener’ and signatures that request to graph.facebook.com APIs.
Users should also double check the authenticity of an update with the manufacturer, pay close attention to updates pushed through adverts and social media, and use one of the best antivirus services available as an additional line of defense.
While this campaign has since been taken down, the attack shows the potential for malicious actors to use Facebook advertising and social media to push further malware on a global scale.
You might also like
Fake facebooks ads are posing as Bitwarden security updates The updates actually install a malicious browser extension The extensions steals personal and financial data from Facebook Bitdefender has warned hackers are using the Facebook advertising platform to trick Bitwarden users into installing a fake security update that steals personal data…
Recent Posts
- I tried this new online AI agent, and I can’t believe how good Convergence AI’s Proxy 1.0 is at completing multiple online tasks simultaneously
- I cannot describe how strange Elon Musk’s CPAC appearance was
- Over a million clinical records exposed in data breach
- Rabbit AI’s new tool can control your Android phone, but I’m not sure how I feel about letting it control my smartphone
- Rabbit AI’s new tool can control your Android phones, but I’m not sure how I feel about letting it control my smartphone
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010