KUALA LUMPUR, September 11 – Palo Alto Networks’ Unit 42 researchers have uncovered a new phishing campaign known as NodeStealer 2.0, which is specifically targeting Facebook business accounts. This campaign employs a lure of free business tools, such as spreadsheet templates, to gain complete control over the targeted accounts. This marks a worrisome trend as threat actors increasingly focus on Facebook business accounts, a trend that emerged around July 2022. NodeStealer, an information-stealing malware, was initially identified in July 2022, and its malicious activities were reported in January 2023 by Meta.

In December 2022, a new version of NodeStealer emerged, involving two Python-written variants with advanced capabilities, including cryptocurrency theft, downloading abilities, and the complete takeover of Facebook business accounts. The primary infection vector for NodeStealer 2.0 is a phishing campaign that revolves around business-related advertising materials. This approach enables threat actors to steal browser cookies, thus hijacking accounts on the Facebook platform, with a specific focus on business accounts. The attackers utilized multiple Facebook pages and user profiles to post enticing information.

Leading victims to download links hosted on recognized cloud file storage providers. Upon clicking these links, a ZIP file containing the malicious info stealer executable would be downloaded to the victim’s device. In a statement, Vicky Ray, Director at Unit 42 Cyber Consulting & Threat Intelligence, Asia Pacific & Japan at Palo Alto Networks, noted, “As of July 2023, Malaysia recorded 29,336,400 Facebook users, comprising 85.1% of its population. This extensive presence potentially exposes Malaysia to considerable risks from NodeStealer, which greatly threatens individuals and organizations.”

He further emphasized the implications of the malware’s capabilities, including its potential to steal browser credentials for further attacks. Facebook business account owners are advised to adopt strong, complex passwords and enable multi-factor authentication to enhance security. Additionally, organizations are encouraged to educate their employees about phishing tactics, particularly the modern, targeted approaches that exploit current events, business needs, and other enticing subjects.