GUEST RESEARCH: Bitdefender Labs has been monitoring the growing trend among cybercriminals who actively exploit social media networks for malvertising. The end goal of these attacks is to hijack accounts and steal personal data through malicious software.
Social media platforms offer immense opportunities for financially motivated threat actors to conduct large-scale attacks against unsuspecting Internet users. Fraudulent and malicious threats are prevalent on all social networks and it has become crucial for users to be aware of the latest tricks that can compromise the security of their accounts, data, reputation and finances.
Cybercriminals always seek to trick users into taking all sorts of unwelcome actions, and one way they achieve this is by abusing the ad network.
Malvertising campaigns take advantage of the tools and methods used by legitimate entities to distribute regular online ads, with cybercriminals submitting infected links onto typical advertisement networks via some form of provocative enticement meant to sway users into clicking on an infected link.
This report focuses on how cybercriminals have adapted NodeStealer attacks – a type of malware used by threat actors to steal browser cookies and login credentials, enabling them to hijack Gmail, Facebook, Outlook, and possibly other accounts – to abuse Meta’s ads network on Facebook and compromise users’ privacy and security. Below is a summary of Bitdefender’s analysis conducted between the 10th and 20th October:
The above information regarding the demographic and reach of the campaign has been collected by tracking the ads on Meta Ad Library.
NodeStealer is a relatively new info-stealer, discovered by Meta’s security team in January 2023, that allows threat actors to steal browser cookies and conduct account takeovers at scale.
The first NodeStealer campaign (documented by Meta) was attributed to threat actors in Vietnam, who custom-built the malicious tool (written in JavaScript and executed through Node.js) to target business users via fake communications through Facebook Messenger. The malware let attackers seize control of business accounts, without the need for any further interactions with the victim, and even bypassed security mechanisms such as two-factor authentication (2FA).
Although the stealer was primarily designed to hijack cookie sessions from web browsers including Google Chrome, Microsoft Edge, Brave and Opera, and take over Facebook accounts, threat actors have worked diligently to equip the malware with new capabilities during the year.
The NodeStealer ‘2.1’ malware discovered by Bitdefender’s researchers is the modernised version of the info-stealer (written in Node), to which cybercriminals have added new features that allow them to obtain unlawful entry into additional platforms (Gmail and Outlook), to steal crypto wallet balances and download additional malicious payloads – components that could have devastating financial and reputational consequences for victims.
The malware Is distributed via Windows executable files disguised as photo albums.
NodeStealer attack saga continues to plague Facebook – this time with a twist
Researchers at Bitdefender Labs have observed a fresh take on NodeStealer attacks deployed on Facebook, with threat actors using compromised business accounts to deliver malicious Ad campaigns to unwary internet users.
According to Bitdefender researchers, threat actors are no longer interested in only hijacking Facebook business accounts – they’ve expanded their attacks to target regular Facebook users by using distinctive methods.
To gain access to users’ accounts and systems, cybercriminals abuse ad credit balances of compromised business accounts to run and manage ads that deliver the malicious payload to their select target audience.
They create a Facebook page under the name “Album Update” (or similar) where they add revealing photos of young women.
Other names of fake profiles include:
After the page is set up, malicious actors begin running ads that promote fake new content and entice users with lewd album covers. Some of the photos advertised appear to have been edited or even AI-generated.
Attackers also use short descriptions to bait users into downloading the media archive, such as “New stuff is online today” and “Watch now before it’s deleted.”
The “Albums,” in fact, point to either Bitbucket or Gitlab repositories that store an archive containing a Windows executable that deploys newer versions of NodeStealer onto the user’s device.
What are consumers’ risks and how can you defend against NodeStealer ad attacks?
Once cybercriminals gain access to users’ cookies using the basic features of NodeStealer, they take over Facebook accounts and access sensitive information.
From there, hackers can attempt to change passwords and add additional security measures to accounts to completely cut off access to the legitimate owner and commit a variety of crimes of fraud. Whether stealing money or scamming new victims via hijacked accounts, this type of malicious attack allows cybercriminals to stay under the radar by sneaking past Meta’s security defences.
The first line of defence against Nodestealer malware delivered via phishing links, attachments or ads, is to always use a security solution on your device and keep it up to date. Anti-malware and anti-virus software keep you and your devices safe from new and existing threats by detecting malware and safely removing or stopping it from causing any damage. Additionally, internet users should always stay vigilant and stick to good cyber hygiene in all online interactions. It’s always best to think twice before you click on unsolicited links associated with alarming notices or ads that prompt you to download provocative media files.
Specifically for this campaign, Facebook users should steer clear of ads that suggest you download photo albums from Bitbucket, Gitlab or Dropbox.
About Bitdefender
Bitdefender provides cybersecurity solutions with leading security efficacy, performance and ease of use to small and medium businesses, mid-market enterprises and consumers. Guided by a vision to be the world’s most trusted cybersecurity solutions provider, Bitdefender is committed to defending organisations and individuals around the globe against cyberattacks to transform and improve their digital experience. bitdefender.com.au/
GUEST EVENT: Digital Transformation Live – Australia's largest ICT trade show – is happening at Sydney's International Convention and Exhibition Centre on 8 and 9 June 2023.
GUEST EVENT: Digital Transformation Live – Australia's largest ICT trade show – is happening at Sydney's International Convention and Exhibition Centre on 8 and 9 June 2023.
New features of the Asana work management platform provide leaders with an unmatched repository of insights into how employees are collaborating across an organisation, thus enabling faster pivots and accelerated business success, according to the company.
Four in five (80%) Australian workers feel that information overload—driven by factors including information overload across devices (37%), constant information 24/7 (34%), too many passwords to remember (33%) or too many apps to check each day (31%)—is contributing to their daily stress, according to new research by software company OpenText.
GUEST OPINION: Pandemic restrictions have caused big changes within many Australian businesses, and one of the most significant has been a rapid increase in the adoption of cloud resources and services.
Working from home in 2022? Often need hardcopy documents? Need a scanner as well as a printer? If you answer "yes" to all these questions, take a look at the Epson ET-4850.
Brother's latest INKvestment all-in-one printers are aimed at the remote workforce.
GUEST OPINION by Joe Slowik, Gigamon: Data exfiltration exists as a cornerstone of malicious cyber operations, yet its nature and impact have changed significantly over the past few years.
Cloud storage service Dropbox is to acquire secure document sharing and analytics company DocSend.
Open-source file syncing and sharing software company Nextcloud has released migration apps to enable users to move from popular proprietary cloud services to a private cloud platform.
Dropbox Family provides up to six people with 2TB of pooled storage to use individually or collectively.
HelloSign electronic signing is now available to all Dropbox users, along with the option of onshore storage of completed documents for some HelloSign users.
Cloud storage service, Dropbox, today announced a new Dropbox Family plan, new features to its Plus plan, native integration with HelloSign, and an App Centre to help users keep their life organised and work moving.
Enterprise document creation and automation provider Templafy is expanding its presence in the Asia Pacific region, establishing an office in Sydney which it says will allow it to better serve new and existing customers in the APAC market.
Epson's new WorkForce ES-500WR is a $699 desktop scanner with a 50-sheet input tray, one-pass duplex operation, and some interesting document and data management features.
Dropbox subsidiary HelloSign is making it easier to use its electronic signing system in larger organisations.
SPONSORED NEWS by Probax.
9 July 2019 Perth, WA - Probax, a leading provider of intelligent data protection and business continuity solutions for Managed Service Providers (MSPs), today launched their latest SaaS protection solution: Dropbox Backup & Archive.
Sydney-based workforce management software solution provider Deputy has closed a $111 million capital raising which has been billed as Australia’s largest ever Series B funding round.
Most cybersecurity is making up for weak platforms. We need to address the fundamentals, design platforms that prevent out-of-bounds access[…]
For most developers the security/performance trade off is still the hardest one to tackle, even as the cost of processing[…]
RISC has been overhyped. While it is an interesting low-level processor architecture, what the world needs is high-level system architectures,[…]
There are two flaws that are widespread in the industry here. The first is that any platform or language should[…]
Ajai Chowdhry, one of the founders and CEO of HCL is married to a cousin of a cousin of mine.[…]