Facebook business owners targeted by hackers

facebook
(Image credit: 123RF)

A new cybercrime group has been identified by Malwarebytes to be targeting business owners who use Facebook's advertising tools.

In a report from the company, Senior Threat Researcher Jérôme Segura noted, “there's been a resurgence in sponsored posts and accounts that impersonate Meta/Facebook's own Ads Manager” promising better ad performance.

The attack, which leads victims to install a malicious Chrome browser extension, looks to have generated more than $180,000 in compromised ad budget to date.

Fake Facebook ad generator

Malicious accounts redirect unsuspecting victims to external phishing domains, which use legitimate branding and favicons to trick users into thinking they are still on the Facebook platform.

Among the malicious downloads is a Chrome extension, which uses a Google Translate icon despite its promise to generate better Facebook ad returns. Segura says:

“A quick look at its source code reveals immediate hex obfuscation in an attempt to hide what it is actually doing.”

Reverse engineering found that the extension indeed has nothing to do with Google Translate, and instead focuses on grabbing Facebook login information.

Malwarebytes has discovered more than 20 similar campaigns, one of which goes on to accidentally leak its own stolen data and, subsequently, Google account information, which has since been passed on to Meta by the researchers.

All in, it looks like more than 800 victims have been taken advantage of worldwide, with around two in five coming from the US. The information, which has been shared with Meta, indicates that the threat actors are from Vietnam and are largely targeting Facebook business accounts.

Malwarebytes suggests that Business Manager accounts should regularly be checked for unknown users. Periodically running malware scans also serves as a valuable exercise that could prevent data and money theft.

In response, a Meta spokesperson told TechRadar Pro in an email that the company "welcome[s] external security research into malware targeting advertising platforms like [Meta's]" and that it has worked with Malwarebytes to take action against this malware.

A recent Meta post highlights some of the work it has done to protect businesses that may be targeted by malware. Meta encourages users to take caution when installing third-party extensions and apps,  to turn on log-in alerts, and to enable Business notifications. Of course, there is also more generic Internet hygiene that all users should follow, including using unique and strong passwords, and enabling two-factor authentication (2FA), 

Craig Hale

With several years’ experience freelancing in tech and automotive circles, Craig’s specific interests lie in technology that is designed to better our lives, including AI and ML, productivity aids, and smart fitness. He is also passionate about cars and the decarbonisation of personal transportation. As an avid bargain-hunter, you can be sure that any deal Craig finds is top value!

Read more
A padlock resting on a keyboard.
Understanding and avoiding malvertizing attacks
Fraude en ligne phishing
Google Search ads are being hacked to steal account info
unblock facebook with vpn
A new Facebook phishing campaign looks to trick you with emails sent from Salesforce
Representational image of a cybercriminal
Criminals are spreading malware disguised as DeepSeek AI
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Microsoft 365 accounts are under attack from new malware spoofing popular work apps
Pirate skull cyber attack digital technology flag cyber on on computer CPU in background. Darknet and cybercrime banner cyberattack and espionage concept illustration.
Mac users targeted with new malware, so be on your guard
Latest in Pro
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
AI quantization
What is AI quantization?
US flags
US government IT contracts set to be centralized in new Trump order
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Google Gemini AI
Gmail is adding a new Gemini AI tool to help smarten up your work emails
Latest in News
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Hatch Restore 3 in Putty
You can finally start your day with The Office theme song, and I couldn't be more excited
Cassian Andor looking nervously over his shoulder in Andor season 2
New Andor season 2 trailer has got Star Wars fans asking the same question – and it includes an ominous call back to Rogue One's official teaser
Ncuti Gatwa as The Fifteenth Doctor in Doctor Who
Disney+ drops new trailer for Doctor Who season 2 that promises an epic adventure across time and space
23andMe
23andMe is bankrupt and about to sell your DNA, here's how to stop that from happening