Eblogtip.com
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions

Archives

  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • December 2022

Categories

  • News
  • Technology
  • Uncategorized
eBlogTip
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions
  • News

This new malware is going after Facebook Business accounts

  • August 2, 2023
Total
0
Shares
0
0
0


A new malware strain has been identified targeting Facebook business accounts and stealing their cryptocurrency, experts have revealed.

A new report from Unit 42, the cybersecurity arm of Palo Alto Networks has identified the malware as NodeStealer, a Python variant of the malware originally written in JavaScript. 

To get people to install NodeStealer, hackers were reaching out via Facebook, offering fake “professional” budget tracking Microsoft Excel and Google Sheets templates. Given that the attackers were going after business accounts, it’s no wonder that they were trying to lure people in by offering business-related tools and assistance.

Idle campaign

The “templates” were hosted on Google Drive, residing in a .ZIP archive. The archive carried the NodeStealer executable which was also capable of deploying additional malware, such as BitRAT and XWorm, as well as disabling Microsoft Defender antivirus and stealing cryptocurrencies through the MetaMask browser addon wallet. 

The strain was used in a malicious campaign that started in December 2022, the researchers said, adding that it’s unlikely that the scheme is still ongoing. 

NodeStealer was first spotted in May 2023 by Meta, when the company described it as a stealer that grabs cookies and passwords stored in browsers. NodeStealer was capable of compromising not just Facebook accounts, but Gmail and Outlook, too.

“NodeStealer poses great risk for both individuals and organizations,” Unit 42 researcher Lior Rochberger said. “Besides the direct impact on Facebook business accounts, which is mainly financial, the malware also steals credentials from browsers, which can be used for further attacks.”

Originally, the attackers were using Facebook business accounts to run malicious advertising campaigns on the platform, and lure the social network’s users to third-party websites where they’d incentivize them to download malware or otherwise share sensitive information.


Source link

Total
0
Shares
Share 0
Tweet 0
Pin it 0
Previous Article
  • Technology

Subaru doubles its plans for new EVs, targeting 8 models by 2028

  • August 2, 2023
View Post
Next Article
  • Technology

Apple Card’s Savings account reaches over $10 billion in deposits

  • August 2, 2023
View Post
You May Also Like
View Post
  • News

Hackers exploit several security flaws in top Qualcomm GPUs

  • October 4, 2023
View Post
  • News

North Korean hackers are targeting aerospace – Lazarus Group tricks employees into installing malware themselves

  • October 4, 2023
View Post
  • News

Major Linux distros targeted by hackers exploiting this significant flaw

  • October 4, 2023
View Post
  • News

Black Friday electric scooter deals 2023: what we expect this year

  • October 4, 2023
View Post
  • News

Payday 3 is getting progression changes after all

  • October 4, 2023
View Post
  • News

Minecraft’s mob vote just got its first entry and perhaps much more

  • October 4, 2023
View Post
  • News

Google Assistant is finally getting Bard’s AI smarts – and it could help run your life

  • October 4, 2023
View Post
  • News

Overwatch 2 Season 7 is bringing some fantastic changes to maps and heroes

  • October 4, 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

eBlogTip.com
  • Categories

Input your search keywords and press Enter.