HomeSecurityOv3r_Stealer malware: Distributed via fake job ads on Facebook

Ov3r_Stealer malware: Distributed via fake job ads on Facebook

Hackers are creating fake job ads on Facebook to trick potential targets into installing a new info-stealer malware , codenamed Ov3r_Stealer.

Ov3r_Stealer info-stealer malware

According to Trustwave SpiderLabs, this malware steals credentials and crypto wallets and sends them to a Telegram channel monitored by its operators.

Additionally, according to The Hacker News, “Ov3r_Stealer collects IP address-based location data, hardware information, passwords, cookies, credit card information, autofill, browser extensions, crypto wallets, Microsoft Office documents, and a list of antivirus products installed on the compromised computer.”

See also: NS-STEALER: Info-stealer malware uses Discord bot to steal data

We don't know what the attackers do with the stolen data, but they could sell it to other threat actors. Additionally, Ov3r_Stealer could gain more capabilities in the future to act as a loader for additional malicious payloads, including ransomware.

How does the attack work?

According to Trustwave, hackers are exploiting fake postings on Facebook and include a malicious PDF file that purports to be a file hosted on OneDrive. Users are asked to click an “Access Document” button embedded within it.

For example, this PDF file was shared by a fake Facebook account impersonating AmazonAndy Jassy, ​​as well as in ads for jobs in the digital advertising industry.

Users who end up clicking the “Access Document” button are presented with an internet shortcut (.URL) file disguised as a DocuSign and hosted on Discord’s content delivery network (CDN). The shortcut file then delivers a control panel item (.CPL) file that is executed using the Windows Control Panel process binary (“control.exe”).

See also: MacOS info-stealer malware evades detection by XProtect

Executing the CPL file retrieves a PowerShell loader (“DATA1.txt”) from a GitHub repository. It then begins launching the final payload, which is the Ov3r_Stealer malware.

It is worth noting that a nearly identical infection chain was recently uncovered by Trend Micro, in relation to another malware , called Phededrone Stealer. In fact, there appear to be similarities in the code.

job postings on Facebook
Ov3r_Stealer malware: Distributed via fake job ads on Facebook

What are the best methods for protecting against info stealer malware?

The first and most important method of protection is awareness and education. Users need to be aware of the techniques attackers use to spread malware so they can identify and avoid them.

Installing reliable security software is another key method of protecting against info-stealer malware, such as Ov3r_Stealer. This software should include antivirus, anti-spyware , and anti-malware features, as well as phishing.

See also: Info-stealer malware targets the online gaming community

It's also important to keep your operating system and all applications up to date. Updates include security fixes that can protect computer from the latest threats.

Using strong passwords and changing them regularly can protect your data from theft. Also, using a password manager can help manage and secure your passwords.

Finally, careful interaction with emails and file attachments is crucial. Never open attachments or click on links from unknown sources.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS