Connect with us

Hi, what are you looking for?

HEADLINES

Palo Alto Networks Unit 42 researchers unveil new phishing campaign named NodeStealer 2.0

The campaign entices victims with free business tools, like spreadsheet templates, to completely take over the accounts. This strategy indicates a concerning trend among threat actors, who have been increasingly targeting Facebook business accounts which emerged around July 2022.

Palo Alto Networks Unit 42 researchers unveiled a new phishing campaign named NodeStealer 2.0, aimed at Facebook business accounts. The campaign entices victims with free business tools, like spreadsheet templates, to completely take over the accounts. This strategy indicates a concerning trend among threat actors, who have been increasingly targeting Facebook business accounts which emerged around July 2022.

In May 2023, Meta released a report on NodeStealer, a new information-stealing malware initially compiled in July 2022. The report highlighted malicious activities involving NodeStealer that were identified in January 2023. In December 2022, a campaign featuring a new version of Nodestealer emerged. This new campaign involved two Python-written variants with enhanced capabilities, including cryptocurrency theft, downloading abilities, and a complete takeover of Facebook business accounts.

NodeStealer 2.0 Phishing Campaign 

The main infection vector was a phishing campaign focusing on advertising materials for businesses, allowing threat actors to steal browser cookies to hijack accounts on the platform, specifically aiming toward business accounts. The threat actor used multiple Facebook pages and users to post information, luring victims to download links from known cloud file storage providers. After clicking on it, a ZIP file was downloaded to the machine containing the malicious info stealer executable. 

Advertisement. Scroll to continue reading.

“In early 2023, Meta reported it has reached 80.30 million Facebook users in the Philippines, equivalent to 69.0 percent of the total population at the start of the year. This extensive presence potentially exposes the country to considerable risks from NodeStealer, which greatly threatens individuals and organizations. Besides the direct impact on Facebook business accounts, which is mainly financial, the malware also steals credentials from browsers, which can be used for further attacks. We encourage all organisations to review their protection policies and use the indicators of compromise (IoCs) provided in this report to address this threat.” said Vicky Ray, Director at Unit 42 Cyber Consulting & Threat Intelligence, Asia Pacific & Japan at Palo Alto Networks.

Facebook business account owners are encouraged to use strong, complex, hard-to-guess passwords and enable multifactor authentication. Take the time to educate your organization on phishing tactics, especially modern, targeted approaches that address current events, business needs, and other appealing topics. 

Advertisement
Advertisement
Advertisement

Like Us On Facebook

You May Also Like

HEADLINES

A calamity fund is designed to provide financial relief in these challenging times, ensuring that you have the resources needed to recover quickly and...

HEADLINES

This is in line with the Philippine government’s efforts to strengthen the security and resilience of the country’s cyberspace under the National Cybersecurity Plan...

HEADLINES

The report shows that 86% of Oracle Java users are migrating all or some of their use with reasons including cost, a preference for...

HEADLINES

By extending Platform Equinix to the Philippines, local businesses can expand globally across 71 markets while overseas companies can seize the digital opportunities presented...

HEADLINES

Converge is breaking ground on Ribbon’s 5 nanometer (nm) - 140Gbaud transmission chipset that will expand its fiber network capacity from its existing 800...

HEADLINES

Alipay+ is the Official Payment Partner of the UEFA EURO 2024, and connects leading e-wallets and bank apps, including European partners like Bluecode and...

HEADLINES

Powered by the all-in-one Genesys Cloudplatform , the ePLDT Next-Gen Contact Center as-a-Service (CCaaS) uses AI to provide a 360-degree view of the end-to-end...

HEADLINES

The upcoming Paris Olympics, the first in-person summer Games since pandemic restrictions were lifted, are expected to attract thousands of tourists. Amid the event,...

Advertisement