HomeSecurityFake Madgicx Plus and SocialMetrics extensions steal Meta accounts

Fake Madgicx Plus and SocialMetrics extensions steal Meta accounts

Cybersecurity researchers have uncovered two new campaigns promoting fake browser extensions, using malicious ads and fake websites to steal sensitive data from Meta accounts.

According to Bitdefender, the malicious ad campaign is designed to promote fake browser extensions called SocialMetrics Pro, which supposedly unlock the blue verification badge for profiles on Meta and Instagram.

See also: Former WhatsApp security chief sues Meta

Meta

At least 37 malicious ads serving the extension in question have been observed. “The malicious ads are accompanied by a video tutorial that guides viewers through the process of downloading and installing a so-called browser extension, which supposedly unlocks the blue verification badge on Facebook or other special features,” the Romanian cybersecurity provider said.

However, the extension – which is hosted on a legitimate cloud service called Box – is capable of collecting session cookies from Facebook and sending them to a bot on Telegram controlled by the attackers. It can also obtain the victim’s IP address by sending a query to ipinfo[.]io/json. Selected variants of the malicious browser add-on have been observed using the stolen cookies to interact with the Facebook Graph API, likely to extract additional information about accounts.

See also: Singapore v. Meta: Injunction to curb fraud on Facebook

Fake Madgicx Plus and SocialMetrics extensions steal Meta accounts

In the past, malware like NodeStealer has leveraged the Facebook Graph API to harvest account budget details. The ultimate goal of these efforts is to sell valuable Facebook Business and Ads accounts on underground forums for profit to other scammers or reuse them to fuel more malicious ad campaigns, leading to more compromised accounts – essentially creating a self-perpetuating cycle.

The campaign features all the “fingerprints” typically associated with Vietnamese-speaking threat actors, who are known to adopt various stealer families to target and gain unauthorized access to Facebook accounts. This hypothesis is also reinforced by the use of Vietnamese language for the guide’s narration and source code annotations.

See also: New agreement between Google and Meta in the cloud industry

Fake Madgicx Plus and SocialMetrics extensions steal Meta accounts

Another campaign targets Meta advertisers with malicious Chrome extensions distributed via fake websites that present themselves as AI-powered ad optimization tools for Facebook and Instagram. At the heart of the operation is a fake platform called Madgicx Plus. Once installed, the extension gains full access to all websites the user visits, allowing attackers to inject arbitrary scripts, modify network traffic, monitor browsing activity, record form inputs, and collect sensitive data. It also prompts users to connect their Facebook and Google accounts to access the service.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS