Hackers are creating fake job ads on Facebook to trick potential targets into installing a new info-stealer malware , codenamed Ov3r_Stealer.

According to Trustwave SpiderLabs, this malware steals credentials and crypto wallets and sends them to a Telegram channel monitored by its operators.
Additionally, according to The Hacker News, “Ov3r_Stealer collects IP address-based location data, hardware information, passwords, cookies, credit card information, autofill, browser extensions, crypto wallets, Microsoft Office documents, and a list of antivirus products installed on the compromised computer.”
See also: NS-STEALER: Info-stealer malware uses Discord bot to steal data
We don't know what the attackers do with the stolen data, but they could sell it to other threat actors. Additionally, Ov3r_Stealer could gain more capabilities in the future to act as a loader for additional malicious payloads, including ransomware.
How does the attack work?
According to Trustwave, hackers are exploiting fake postings on Facebook and include a malicious PDF file that purports to be a file hosted on OneDrive. Users are asked to click an “Access Document” button embedded within it.
For example, this PDF file was shared by a fake Facebook account impersonating AmazonAndy Jassy, as well as in ads for jobs in the digital advertising industry.
Users who end up clicking the “Access Document” button are presented with an internet shortcut (.URL) file disguised as a DocuSign and hosted on Discord’s content delivery network (CDN). The shortcut file then delivers a control panel item (.CPL) file that is executed using the Windows Control Panel process binary (“control.exe”).
See also: MacOS info-stealer malware evades detection by XProtect
Executing the CPL file retrieves a PowerShell loader (“DATA1.txt”) from a GitHub repository. It then begins launching the final payload, which is the Ov3r_Stealer malware.
It is worth noting that a nearly identical infection chain was recently uncovered by Trend Micro, in relation to another malware , called Phededrone Stealer. In fact, there appear to be similarities in the code.

What are the best methods for protecting against info stealer malware?
The first and most important method of protection is awareness and education. Users need to be aware of the techniques attackers use to spread malware so they can identify and avoid them.
Installing reliable security software is another key method of protecting against info-stealer malware, such as Ov3r_Stealer. This software should include antivirus, anti-spyware , and anti-malware features, as well as phishing.
See also: Info-stealer malware targets the online gaming community
It's also important to keep your operating system and all applications up to date. Updates include security fixes that can protect computer from the latest threats.
Using strong passwords and changing them regularly can protect your data from theft. Also, using a password manager can help manage and secure your passwords.
Finally, careful interaction with emails and file attachments is crucial. Never open attachments or click on links from unknown sources.
Source: thehackernews.com
