HomeSecurityNodeStealer: The new malware discovered by Facebook

NodeStealer: The new malware discovered by Facebook

Facebook has discovered a new malware called “NodeStealer” that steals browser cookies.

See also: YouTube Videos distribute Aurora Stealer malware

NodeStealer

Downloading cookies containing valid user session tokens is a tactic that is becoming increasingly popular among cybercriminals, as it allows them to steal accounts without having to steal credentials or interact with the target, while also bypassing two-factor authentication protections.

According to a new blog post from Facebook's security team, the company detected NodeStealer very early in its distribution campaign, just two weeks after its initial deployment. The company has since shut it down and helped affected users recover their accounts.

In late January 2023, Facebook engineers discovered the NodeStealer malware and attributed the attacks to Vietnamese actors. NodeStealer is malware that uses the JavaScript and runs through Node.js.

Node.js is a software development tool that can run on various operating systems, including Windows , macOS, and Linux. However, this also makes it potentially dangerous because it can be used by malware. However, it is worth noting that many antiviruses do not detect this software as malicious on VirusTotal.

NodeStealer is a 46-51 MB Windows executable file that is disguised to look like a PDF or Excel file with a suitable name, arousing curiosity in the recipient. This file is distributed to users.

Upon startup, Node.js uses the module's autostart and adds a new identification key to the computer to ensure the suitcase persists across reboots.

The malware's main goal is to steal cookies and credentials of Facebook, Gmail, and Outlook accounts. These are stored in Chrome-based browsers, such as Google Chrome, Microsoft Edge, Brave, Opera, etc.

See also: Google Ads: They distribute malware

Facebook

Typically, this data is encrypted in the browsers’ SQLite database. However, reversing this encryption is a trivial process that is implemented by all modern information thieves, who simply retrieve the base64-encoded decryption key from Chromium’s “Local State” file.

To avoid detection by systems , NodeStealer hides these requests behind the victim's IP address and uses cookies and system configuration to appear like a genuine user.

The key information the malware seeks is the ability of the Facebook account to run advertising campaigns, which malicious actors use to promote misinformation or lead unsuspecting audiences to other malware distribution sites.

Following the discovery, Facebook announced that it had identified the threat actor's server and added it to its list of blocked domains, before removing it on January 25, 2023. In today's report, Facebook provided further information about the DuckTail and ChatGPT, including malicious program add-ons.

See also: Android certificates are used for malware

For those interested, Facebook has uploaded its Indicator of Compromise (IOC) data to its public GitHub , which concerns the NodeStealer, DuckTail, and ChatGPT emulator malware.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS