Press ESC to close

Unmasking the SYS01 Infostealer Threat: Bitdefender Labs Tracks Global Malvertising Campaign Targeting Meta Business Pages

CategoryDetails
Threat ActorsCybercriminals behind the SYS01 InfoStealer malvertising campaign.
Campaign OverviewA growing malvertising campaign using Meta’s advertising platform to distribute SYS01 InfoStealer malware, impersonating popular brands to target users across multiple platforms.
Target Regions (Victims)Global reach, particularly targeting North America, EU, Australia, and Asia. Victims mainly males aged 45+ years.
Methodology– Malicious ads impersonating trusted brands.
– Uses ElectronJs to deliver malware.
– Malicious domains for distribution and C2 operations.
– Ads distributed via platforms like MediaFire.
Product TargetedPopular software tools (CapCut, Office 365), video streaming services (Netflix), VPNs, and video games.
Malware ReferenceSYS01 InfoStealer
Tools UsedElectronJs, PowerShell scripts, 7zip (for extraction), IonCube Loader (for encoding PHP scripts), Task Scheduler for persistence.
Vulnerabilities ExploitedMalicious ad placements, fake software downloads, social engineering through impersonated brands.
TTPs– Use of decoy apps (disguised malware).
– Dynamic evasion and obfuscation of malicious payloads.
– PowerShell scripts for execution and persistence.
– Malware communicated via C2 domains.
AttributionThe campaign is attributed to cybercriminals using Meta’s ad platform for malvertising, though exact identity is not provided.
Recommendations– Users should avoid downloading software from untrusted ads.
– Implement endpoint protection and malware detection tools.
– Educate users on identifying fake ads.
SourceBitdefender

Read full article : https://www.bitdefender.com/en-us/blog/labs/unmasking-the-sys01-infostealer-threat-bitdefender-labs-tracks-global-malvertising-campaign-targeting-meta-business-pages

Disclaimer: The above summary has been generated by an AI language model

Leave a Reply

Your email address will not be published. Required fields are marked *