New Credential-Stealing Campaign Via Facebook Detected
Credential-stealing malware StealC v2 is spreading through fake Facebook support messages.
The research team at security vendor Kaspersky has detected a new phishing wave on Facebook that installs malware to steal logins, browser data and cryptocurrency wallets.
The researchers say more than 400 incidents have been recorded since late August, with victims identified in Turkey, India, and Indonesia.
The campaign uses social engineering tactics to trick users into downloading StealC v2 malware. This, in turn, harvests users' personal details like passwords, cookies, screenshots and cryptocurrency wallet data.
Marc Rivero, lead security researcher at the Kaspersky Global Research and Analysis Team, said: “Cybercriminals often exploit users’ fear of losing account access and a perceived sense of urgency. This pressure can lead individuals to act without caution, increasing the risk of infection by malware such as StealC v2.”
How The Campaign Works
According to Kaspersky, contact is initiated through Facebook messages that masquerade as official notifications claiming the recipient's account has been suspended due to suspicious activity. These deceptive messages contain links that redirect victims to convincing fake support pages designed to mirror legitimate Facebook interfaces.
When users click the provided "Appeal" button to restore their supposedly blocked accounts, they unknowingly trigger the download of a malicious script. This script then installs StealC v2 onto their devices, giving attackers access to sensitive personal and financial information.
StealC v2 is said to have evolved from its predecessor, which first appeared on dark web marketplaces in 2023. This updated version operates under a Malware-as-a-Service model, which makes it easily accessible to cybercriminals.
Staying Alert To Social Scams
The campaign highlights how cybercriminals exploit Facebook’s support system format to trick users. Similar scams have surfaced in the past, where fraudulent notifications urged people to act quickly to avoid account suspension. Earlier this year, Computing reported a dramatic increase in phishing-as-a-service incidents, as recorded by Barracuda Networks researchers. Before that, cybersecurity firm F-Secure revealed that 62 percent of Facebook users encountered a scam each, with fraudsters increasingly targeting business pages and personal accounts through fake support messages.
To reduce exposure to Facebook phishing scams, Kaspersky advises users to scrutinise links for spelling errors or redirects, be wary of unsolicited messages that demand immediate action, and avoid sharing two-factor authentication codes. The researchers also stress the importance of verifying suspicious alerts through official channels rather than relying on links shared via private messages.
This article originally appeared on our sister site Computing.