nodestealer

Malware updated 7 months ago (2024-05-04T17:46:07.396Z)
Download STIX
Preview STIX
NodeStealer, a novel malware family first identified by Meta's security team in January 2023, is designed to exploit Meta's ad network on Facebook and poses a significant threat to user privacy and security. This malicious software operates as an info-stealer capable of hijacking browser cookies and executing account takeovers at scale. The seemingly innocuous "Albums" advertised in campaigns serve as gateways to repositories on platforms like Bitbucket and Gitlab, which conceal a Windows executable poised to unleash the insidious NodeStealer onto the unsuspecting user's device. The malware was executed using the cross-platform, open-source JavaScript runtime environment Node.js. Its upgraded version, NodeStealer 2.1, boasts new features that extend its reach to additional platforms like Gmail and Outlook, aiming to steal crypto wallet balances and unleash further malicious payloads. It has been used in previous campaigns where hackers hijacked Facebook business accounts, leading to cryptocurrency theft. Threat actors have employed innovative methods, including the exploitation of compromised business accounts to target regular users. However, Meta acted swiftly upon identifying NodeStealer, disrupting the malware family within weeks after it emerged. Meta revealed that it first spotted NodeStealer roughly two weeks after it was initially deployed and immediately took action to neutralize it, including contacting appropriate service providers. According to Meta, the disruption was successful, with no new NodeStealer samples observed since February 27, 2023. The findings were introduced by Nimmo and Hutchins at CYBERWARCON and detailed in subsequent interviews.
Description last updated: 2024-05-04T16:28:26.728Z
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Malware
Facebook
Outlook
Windows
Meta
Phishing
Exploit
Infostealer
Credentials
Payload
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Malware
To see the evidence that has resulted in these malware associations, create a free account
Alias DescriptionAssociation TypeVotes
The Ducktail Malware is associated with nodestealer. "Ducktail" is a malicious software (malware) first observed in 2022, specifically designed to target Facebook business accounts. The malware was discovered by Zscaler, a leading cybersecurity firm, and it's suspected to originate from threat actors based in Vietnam. Ducktail not only infiltrates sysUnspecified
5
Source Document References
Information about the nodestealer Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
CERT-EU
8 months ago
CERT-EU
9 months ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
Bitdefender
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
2 years ago
CERT-EU
2 years ago
CERT-EU
2 years ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
2 years ago
CERT-EU
a year ago
CERT-EU
a year ago