Password-stealing malware targets thousands of Facebook business

Messenger
(Image credit: Meta)

New research published by Guardio Labs’s Oleg Zaytsev has revealed the extent of ongoing Messenger-based attacks targeting business owners on Facebook in recent weeks.

The surge in attacks is attributable to a Vietnamese-based group that has been seeing particular success in its campaign, succeeding in its bid to compromise around one account in every 70 it tries.

According to Zaytsev, millions of businesses have already been targeted on the platform that has become known as one of the most cost-effective online trading and marketing methods.

Facebook business owners warned of cyberattacks

Rather than relying on the basic principles of phishing, whereby users willingly share their credentials via an illegitimate, malicious site, this campaign focuses on spreading malware designed to intercept these credentials.

Zaytsev says that the attacks begin with messages from what look like prospective customers, which serve as a decoy to let the business owners’ guards down.

Ultimately, the malicious stealer payload is deployed, targeting all browsers installed on a victim’s machine. The Python script is designed to obtain session cookies, which are then sent to the threat actor’s instant messaging channels - specifically, Telegram and Discord.

Different message variations and Unicode characters are designed to create a multitude of individual messages as the threat actor seeks to avoid detection by Messenger’s built-in scanners.

Zaytsev added that two particular pieces of evidence suggest the campaign’s link to a Vietnamese group - a Vietnamese message that is sent to the Telegram bot and the inclusion of the ‘Coc Coc’ browser in the list of browsers that are targeted - one that is especially popular in the country.

Chrome, Firefox, Edge, Opera, Brave, and other Chromium-based browsers look to be affected by the script.

The blog post ends with a message regarding the stark reality of our cyber landscape: vigilance is key in a world where “you can never know where the next punch will come from.”

More broadly, users can follow good practices such as exercising caution with external links and monitoring online accounts for suspicious activity to protect their digital footprints.

More from TechRadar Pro

TOPICS
Craig Hale

With several years’ experience freelancing in tech and automotive circles, Craig’s specific interests lie in technology that is designed to better our lives, including AI and ML, productivity aids, and smart fitness. He is also passionate about cars and the decarbonisation of personal transportation. As an avid bargain-hunter, you can be sure that any deal Craig finds is top value!

Read more
unblock facebook with vpn
A new Facebook phishing campaign looks to trick you with emails sent from Salesforce
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Microsoft 365 accounts are under attack from new malware spoofing popular work apps
Best email services: image of email with one unread message alert
Over 400 million unwanted and malicious emails were received by businesses in 2024
Phishing
Corporate executives are being increasingly targeted by AI phishing scams
Fraude en ligne phishing
Google Search ads are being hacked to steal account info
Malware worm
Coordinated global mobile malware campaign targets banking apps and cryptocurrency platforms
Latest in Security
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
Google Chrome
Google Chrome security flaw could have let hackers spy on all your online habits
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Latest in News
A young woman is working on a laptop in a relaxed office space.
I’ll admit, Microsoft’s new Windows 11 update surprised me with its usefulness, providing accessibility fixes, a gamepad keyboard layout, and PC spec cards
inZOI promotional material.
inZOI has become the most wishlisted game on Steam, but I wouldn't get too caught up in the hype
Xbox Series X and Xbox wireless controller set to a green background
Xbox Insiders are currently testing a new Game Hub feature that looks useful, but I've got mixed feelings about it
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Nespresso Vertuo Pop machine in Candy Pink with coffee drinks and capsules
My favorite Nespresso coffee maker just got a fresh new makeover, and now I love it even more
Microsoft Surface Laptop and Surface Pro devices on a table.
Hate Windows 11’s search? Microsoft is fixing it with AI, and that almost makes me want to buy a Copilot+ PC