Skip to content
  Monday 16 June 2025
  • Home
  • Attack
  • Malware
  • Cloud
  • Data
  • Technology
  • World of tech
Trending
July 15, 2023TeamTNT’s Cloud Credential Stealing Campaign Now Targets Azure and Google Cloud July 10, 2023Ukrainian Agencies, NATO Targeted With RATs Ahead of Summit August 15, 2023Live Webinar | Government Intervention: The Rise of the SBOM and the Evolution of Software Supply Chain SecurityWebinar. January 17, 2025How to Bring Zero Trust to Wi-Fi Security with a Cloud-based Captive Portal? July 9, 2023Improve Your Security WordPress Spam Protection With CleanTalk Anti-Spam September 20, 2024How to Future-Proof a VoIP Phone System January 4, 2024SpaceX charged with illegally firing workers who spoke critically of Elon Musk — Read the full complaint May 5, 2025TeleMessage Goes Dark After Trump Adviser Photo Fallout January 28, 2025U.S. Navy bans use of DeepSeek due to ‘security and ethical concerns’ June 14, 2024This fintech configures expense cards to block misuse — and investors just backed it with millions
  • Home
  • Attack
  • Malware
  • Cloud
  • Data
  • Technology
  • World of tech
  Attack  Vietnamese Hackers Deploy Python-Based Stealer via Facebook Messenger
Attack

Vietnamese Hackers Deploy Python-Based Stealer via Facebook Messenger

adminadmin—September 11, 20230
FacebookTwitterPinterestLinkedInTumblrRedditVKWhatsAppEmail


Sep 11, 2023THNMalware / Social Media

Facebook Messenger

A new phishing attack is leveraging Facebook Messenger to propagate messages with malicious attachments from a “swarm of fake and hijacked personal accounts” with the ultimate goal of taking over the targets’ accounts.

“Originating yet again from a Vietnamese-based group, this campaign uses a tiny compressed file attachment that packs a powerful Python-based stealer dropped in a multi-stage process full of simple yet effective obfuscation methods,” Guardio Labs researcher Oleg Zaytsev said in an analysis published over the weekend.

In these attacks, dubbed MrTonyScam, potential victims are sent messages that entice them into clicking on the RAR and ZIP archive attachments, leading to the deployment of a dropper that fetches the next-stage from a GitHub or GitLab repository.

This payload is another archive file that contains a CMD file, which, in turn, harbors an obfuscated Python-based stealer to exfiltrate all cookies and login credentials from different web browsers to an actor-controlled Telegram or Discord API endpoint.

Cybersecurity

A clever tactic adopted by the adversary involves deletes all cookies after stealing them, effectively logging victims out of their own accounts, at which point the scammers hijack their sessions using the stolen cookies to change their passwords and seize control of them.

More stories

New Grandoreiro Banking Malware Variants Emerge with Advanced Tactics to Evade Detection

October 23, 2024

AWS Default IAM Roles Found to Enable Lateral Movement and Cross-Service Exploitation

May 20, 2025

How to Achieve the Best Risk-Based Alerting (Bye-Bye SIEM)

February 19, 2024

Trump Terminates DHS Advisory Committee Memberships, Disrupting Cybersecurity Review

January 22, 2025

The threat actor’s links to Vietnam comes from the presence of Vietnamese language references in the source code of the Python stealer and the inclusion of Cốc Cốc, a Chromium-based browser popular in the country.

Despite the fact that triggering the infection requires user interaction to download a file, unzip, and execute the attachment, Guardio Labs found that the campaign has witnessed a high success rate where 1 out of 250 victims are estimated to have been infected over the last 30 days alone.

Facebook Messenger

A majority of the compromises have been reported in the U.S., Australia, Canada, France, Germany, Indonesia, Japan, Nepal, Spain, the Philippines, and Vietnam, among others.

“Facebook Accounts with reputation, seller rating, and high number of followers can be easily monetized on dark markets,” Zaytsev said. “Those are used to reach a broad audience to spread advertisements as well as more scams.”

UPCOMING WEBINAR

Way Too Vulnerable: Uncovering the State of the Identity Attack Surface

Achieved MFA? PAM? Service account protection? Find out how well-equipped your organization truly is against identity threats

Supercharge Your Skills

The disclosure comes days after WithSecure and Zscaler ThreatLabz detailed new Ducktail and Duckport campaigns that target Meta Business and Facebook accounts using malverposting tactics.

“The Vietnamese-centric element of these threats and high degree of overlaps in terms of capabilities, infrastructure, and victimology suggests active working relationships between various threat actors, shared tooling and TTPs across these threat groups, or a fractured and service-oriented Vietnamese cybercriminal ecosystem (akin to ransomware-as-a-service model) centered around social media platforms such as Facebook,” WithSecure noted.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.





Source link

FacebookTwitterPinterestLinkedInTumblrRedditVKWhatsAppEmail

admin

Qualcomm says it will supply Apple with 5G modems for iPhones through 2026
Biden says global warming topping 1.5 degrees in the next 10 to 20 years is scarier than nuclear war
Related posts
  • Related posts
  • More from author
Attack

Malicious PyPI Package Masquerades as Chimera Module to Steal AWS, CI/CD, and macOS Data

June 16, 20250
Attack

Discord Invite Link Hijacking Delivers AsyncRAT and Skuld Stealer Targeting Crypto Wallets

June 14, 20250
Attack

Over 269,000 Websites Infected with JSFireTruck JavaScript Malware in One Month

June 13, 20250
Load more

Whoops, you're not connected to Mailchimp. You need to enter a valid Mailchimp API key.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Read also
Attack

Malicious PyPI Package Masquerades as Chimera Module to Steal AWS, CI/CD, and macOS Data

June 16, 20250
Malware

Microsoft-Signed Firmware Module Bypasses Secure Boot

June 15, 20250
Attack

Discord Invite Link Hijacking Delivers AsyncRAT and Skuld Stealer Targeting Crypto Wallets

June 14, 20250
Malware

Black Basta Leaks Highlight Phishing, Google Takeover Risks

June 14, 20250
Malware

2 Software Firms Report Major Health Data Theft Hacks

June 13, 20250
Malware

Guardz Snags $56M to Grow AI Cybersecurity Platform for MSPs

June 13, 20250
Load more

Recent Posts

  • Malicious PyPI Package Masquerades as Chimera Module to Steal AWS, CI/CD, and macOS Data
  • Microsoft-Signed Firmware Module Bypasses Secure Boot
  • Discord Invite Link Hijacking Delivers AsyncRAT and Skuld Stealer Targeting Crypto Wallets
  • Black Basta Leaks Highlight Phishing, Google Takeover Risks
  • 2 Software Firms Report Major Health Data Theft Hacks

    © 2022
    • Home
    • Attack
    • Cloud
    • Data
    • Malware
    • Technology
    • World of tech
    • Privacy
    • Contact