Facebook Malvertising Epidemic – Unraveling a Persistent Threat: SYS01
Trustwave SpiderLabs discovered a malvertisement campaign utilizing a new version of the SYS01 stealer. At a high level, this stealer is designed to take over Facebook accounts, steal credential information from affected users’ browsers, and then leverage legitimate accounts to further the spread of the malware.
This report breaks down the various elements of the malware infection chain as well as a complete reverse engineering analysis of the malware itself. The associated threat actors are continuously evolving, and this research will expose the modified tactics and campaign ads being used, which have changed over time to evade detection and improve targeting.