HomeSecuritySILENTFADE: The long-running malware campaign targeting Facebook Ads

SILENTFADE: The long-running malware campaign targeting Facebook Ads

Facebook has released details about a long-running ad fraud campaign that has been ongoing since 2016 and is targeting Facebook Ads users with the SilentFade (short for “Silent Facebook Ad Execution with Exploits”) malware. The hackers behind this campaign aim to steal Facebook credentials and browser cookies.

According to the tech giant, the malware is linked to Chinaand allowed hackers to steal $4 million from users’ advertising accounts. The hackers first compromised users’ Facebook accounts and then used them to steal browser cookies and conduct malicious activities, including promoting malicious ads. Facebook detected the malware campaign in December 2018 when it noticed an increase in suspicious traffic to several Facebook endpoints.

SilentFade-malware Facebook campaign

Facebook researchers Sanchit Karve and Jennifer Urgilez reported this week at the Virus Bulletin 2020 that they discovered interesting techniques used to compromise user accounts to commit ad fraud. The attackers primarily ran malicious advertising campaigns, often in the form of pharmaceutical pill ads and spam messages featuring fake celebrities.

Facebook confirmed that the initial attack vector was not its platform, as SilentFade was not spread through Facebook or its products. Experts noted that it was usually bundled with potentially unwanted programs (PUPs).

SilentFade-malware Facebook campaign

Once installed, SilentFade allows attackers to steal only stored Facebook credentials and cookies from popular browsers, such as Internet Explorer, Chromium , and Firefox. However, SilentFade's credential stealing component only stole stored Facebook credentials and cookies located on the compromised computer. Experts also pointed out that cookies are more valuable than passwords because they contain session tokens, which are post-authentication tokens. This use of compromised credentials runs the risk of compromising accounts protected by two-factor authentication (2FA), which SilentFade cannot bypass.

Experts explained that all Chromium and Firefox-based browsers store credentials and cookies in SQLite databases. A malware running on an infected endpoint could access the cookie store if it knows its location in various browsers. The malware consists of three to four components, the main download component of which is included in PUP packages.

The downloader application either downloads a standalone malware component or a Windows installed as “AdService” or “HNService”. The service is responsible for persisting across reboots and for dropping both 32-bit and 64-bit DLLs in the Chrome application directory. The proxy DLLs make requests to the real winhttp.dll, but make requests to facebook.com through the Chrome process, avoiding dynamic anti-malware detection by mimicking “innocent” network requests.

When stealing Facebook-related credentials, SilentFade obtains a Facebook account's metadata (payment information and the total amount previously spent on Facebook ads) using the Facebook Graph API.
The malware sends the data to servers in the form of JSON encrypted blocks via custom HTTP headers.

SilentFade-malware Facebook campaign

SilentFade implements multiple evasion techniques, can detect virtual machines, and disable Facebook security alerts from compromised accounts.

The C2 server stored the data it received from the infected target and recorded the IP address of the incoming request for geolocation purposes. Geolocation is important to the scammers’ scheme because the attackers intentionally used the stolen credentials near the infected device’s location.

Additionally, as Security Affairs reports, Facebook accounts with associated credit cards were used to promote malicious ads on Facebook. Facebook experts pointed out that financial data such as bank account and credit card numbers were never exposed to the attackers because Facebook does not make them visible through the desktop website or the Graph API.

Experts also uncovered other malware campaigns linked to China, some of which are still ongoing. The hackers used multiple malicious codes under the names StressPaint, FacebookRobot, and Scranos.

campaigns

Facebook stressed that it expects more and more malware campaigns to occur, especially on platforms that serve large audiences. Therefore, only through user education and strong partnerships across the security industry can any malware campaign be effectively mitigated and addressed.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS