Cybercriminals are using professional pages and Facebook ads to promote fake Windows, which infect users with info-stealing malware.

Trustwave researchers, who monitored the distribution campaigns of the SYS01 malware, said that fake downloads for pirated games and software are also being used.
Malicious Facebook ads
Attackers are delivering ads promoting Windows themes, free game downloads, and software activation cracks for popular applicationsin order to attract unsuspecting users.
These ads are promoted through new Facebook business pages or through compromised accounts. The compromised pages are renamed to match the theme of their ad. Compromising pages allows attackers to exploit an existing follower base.
See also: Microsoft SmartScreen vulnerability used to distribute info-stealer malware
Trustwave threat actors remove thousands of ads for each campaign.
When a Facebook user clicks on the ad, they are taken to web pages hosted on Google Sites or True Hosting that pretend to be download pages for the ad's promoted content.
True Hosting pages are primarily used to promote a website called Blue-Software that supposedly offers free software and game downloads.
Clicking on the “Download” buttons will download a ZIP file with the name of the specific item to your device. For example, the download of the fake Windows themes contains a file named “Awesome_Themes_for_Win_10_11.zip”. The equivalent for Photoshop is “Adobe_Photoshop_2023.zip”.
While users may think they are receiving a free application, game, or Windows theme, the file actually contains the info-stealing malware SYS01.
See also: Mac users exposed to info-stealer malware via Google Ads
When the main executable is loaded, it uses DLL sideloading to load a malicious DLL, which begins setting up the malware. This includes running PowerShell scripts to prevent the malware from running in a virtual environment, adding folder exclusions to Windows Defender, and configuring a PHP operating environment to load malicious PHP scripts.
The main payload of the info-stealing malware SYS01 consists of PHP scripts that create scheduled tasks for persistence and data theft from the device.
The stolen data includes cookies , credentials stored in the browser, browser history, and cryptocurrency wallets.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The malware also steals personal and professional information from the victim's Facebook account.
The stolen data is temporarily stored in the %Temp% before being sent to the attackers.
Stolen cookies and passwords can later be sold to other threat actors or used to compromise further accounts.
Trustwave says the malicious ads are not limited to Facebook, as similar accounts have also been found on LinkedIn and YouTube.
See also: CoralRaider group promotes info-stealer malware through attacks

Protection from info-stealing malware
Static detection methods for security are not enough to avoid malware. A more robust approach should incorporate antivirus software, equipped with advanced analysis capabilities.
security training . Information is also crucial. This means knowing how to recognize and avoid phishing attacks, which attackers often use to install info-stealing malware
It's also important to keep your operating system and applications up to date. These updates often include security fixes that can protect your computer from the latest threats.
Also, don't forget to use firewalls and monitor network traffic to help you immediately detect suspicious activity. Users are also advised to avoid executable files downloaded from strange websites.
Finally, using strong passwords and enabling two-factor authentication can provide an extra layer of protection. This can make it harder for attackers to gain access to your account, even if they manage to steal your password.
Source: www.bleepingcomputer.com
