New NodeStealer Variant Targeting Facebook Business Accounts and Crypto Wallets

Teilen:

Cybersecurity researchers have unearthed a Python variant of a stealer malware NodeStealer that’s equipped to fully take over Facebook business accounts as well as siphon cryptocurrency.

Palo Alto Networks Unit 42 said it detected the previously undocumented strain as part of a campaign that commenced in December 2022. There is no evidence to suggest that the cyber offensive is currently active.

NodeStealer was first exposed by Meta in May 2023, describing it as a stealer capable of harvesting cookies and passwords from web browsers to compromise Facebook, Gmail, and Outlook accounts. While the prior samples were written in JavaScript, the latest versions are coded in Python.

NodeStealer poses great risk for both individuals and organizations, Unit 42 researcher Lior Rochberger said. Besides the direct impact on Facebook business accounts, which is mainly financial, the malware also steals credentials from browsers, which can be used for further attacks.

The attacks start with bogus messages on Facebook that purportedly claim to offer free professional budget tracking Microsoft Excel and Google Sheets templates, tricking victims to download a ZIP archive file hosted on Google Drive.

The ZIP file embeds within it the stealer executable that, besides capturing Facebook business account information, is designed to download additional malware such as BitRAT and XWorm in the form of ZIP files, disable Microsoft Defender Antivirus, and carry out crypto theft by using MetaMask credentials from Google Chrome, Cốc Cốc, and Brave web browsers.

The downloads are accomplished by means of a User Account Control (UAC) bypass technique that employs the fodhelper.exe to execute PowerShell scripts that retrieve the ZIP files from a remote server.

It’s worth noting that the FodHelper UAC bypass method has also been adopted by financially motivated threat actors behind the Casbaneiro banking malware to obtain elevated privileges over infected hosts.

Unit 42 said it further spotted an upgraded Python variant of NodeStealer that goes beyond credential and crypto theft by implementing anti-analysis features, parsing emails from Microsoft Outlook, and even attempting to take over the associated Facebook account.

Once the necessary information is collected, the files are exfiltrated through the Telegram API, after which they are deleted from the machine to erase the trail.

NodeStealer also joins the likes of malware like Ducktail that are part of a growing trend of Vietnamese threat actors looking to break into Facebook business accounts for advertising fraud and propagating malware to other users on the social media platform.

The development comes as threat actors have been observed leveraging WebDAV servers to deploy BATLOADER, which is then used to distribute XWorm as part of a multi-stage phishing attack.

Facebook business account owners are encouraged to use strong passwords and enable multi-factor authentication, Rochberger said. Take the time to provide education for your organization on phishing tactics, especially modern, targeted approaches that play off current events, business needs and other appealing topics.

 

(c) Thin

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
6:48 am, Mai 24, 2025
Wetter-Symbol 13°C
L: 13° | H: 14°
broken clouds
Luftfeuchtigkeit: 90 %
Druck: 1013 mb
Wind: 10 mph SW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 75%
Regen Chance: 0%
Sichtbarkeit: 5 km
Sonnenaufgang: 4:56 am
Sonnenuntergang: 8:58 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
13° | 14°°C 1 mm 100% 13 mph 92 % 1013 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
13° | 20°°C 0.93 mm 93% 16 mph 90 % 1015 mb 0 mm/h
Mo. Mai 26 10:00 pm
Wetter-Symbol
10° | 17°°C 1 mm 100% 13 mph 79 % 1018 mb 0 mm/h
Di. Mai 27 10:00 pm
Wetter-Symbol
13° | 20°°C 1 mm 100% 14 mph 91 % 1017 mb 0 mm/h
Mi. Mai 28 10:00 pm
Wetter-Symbol
14° | 21°°C 1 mm 100% 16 mph 97 % 1018 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
13° | 13°°C 1 mm 100% 10 mph 90 % 1013 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
14° | 16°°C 0.24 mm 24% 10 mph 92 % 1013 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
19° | 22°°C 0 mm 0% 13 mph 70 % 1012 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
24° | 24°°C 0 mm 0% 13 mph 54 % 1011 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
19° | 19°°C 0.43 mm 43% 9 mph 77 % 1011 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
16° | 16°°C 0 mm 0% 11 mph 88 % 1010 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
15° | 15°°C 0 mm 0% 12 mph 85 % 1009 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
15° | 15°°C 0.93 mm 93% 15 mph 90 % 1007 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€95,255.86
-2.24%
Ethereum(ETH)
€2,242.40
-5.30%
Fesseln(USDT)
€0.88
0.02%
XRP(XRP)
€2.06
-4.53%
Solana(SOL)
€154.01
-3.84%
USDC(USDC)
€0.88
0.00%
Dogecoin(DOGE)
€0.200719
-7.53%
Shiba Inu(SHIB)
€0.000012
-7.05%
Pepe(PEPE)
€0.000012
-10.71%
Peanut das Eichhörnchen(PNUT)
€0.306300
-7.81%
Nach oben scrollen