Security News > 2024 > February > Facebook ads push new Ov3r_Stealer password-stealing malware

Facebook ads push new Ov3r_Stealer password-stealing malware
2024-02-07 21:24

A new password-stealing malware named Ov3r Stealer is spreading through fake job advertisements on Facebook, aiming to steal account credentials and cryptocurrency.

The fake job ads are for management positions and lead users to a Discord URL where a PowerShell script downloads the malware payload from a GitHub repository.

The malware inspects the system services configuration in the Windows Registry, possibly to identify potential targets, and can search for document files in local directories.

The researchers note code similarities between Ov3r Stealer and Phemedrone, a C# stealer, which might have been used as a basis for the new malware.

Steam game mod breached to push password-stealing malware.

Rhadamanthys Stealer malware evolves with more powerful features.


News URL

https://www.bleepingcomputer.com/news/security/facebook-ads-push-new-ov3r-stealer-password-stealing-malware/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Facebook 29 0 11 46 54 111