Fabookie
Malware⚠️ Overview
Fabookie is a Windows-based information stealer first documented by Zscaler ThreatLabz in August 2022, categorized as a stealer malware that targets browser credentials, cryptocurrency wallets, and session cookies. It is believed to be operated by a Russian-speaking threat actor known as “Fabookie_admin” who markets the malware on underground forums as a commodity stealer with a subscription-based model.
🔧 Technical Capabilities
Fabookie steals data from Chromium-based browsers (Chrome, Edge, Brave, Opera) and Firefox by reading local SQLite databases and decrypting saved credentials using Windows DPAPI. It targets cryptocurrency wallet extensions (MetaMask, Coinbase Wallet, Binance Chain Wallet) by scanning browser extension directories for seed phrases and private keys. The malware uses a custom C2 protocol over HTTPS with JSON payloads, communicates to hardcoded IP addresses or domains, and employs process hollowing to evade detection by injecting into legitimate processes like svchost.exe. Persistence is achieved via a scheduled task named “FabookieUpdateTask” and a registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. It checks for sandbox environments by enumerating running processes (e.g., wireshark.exe, vboxservice.exe) and terminates itself if detected.
📜 History & Notable Incidents
Fabookie first appeared in August 2022, and by November 2022 Zscaler reported a campaign targeting users in the United States, Brazil, and India via phishing emails containing a malicious Excel attachment (CVE-2017-0199 exploited to download the payload). No high-profile corporate victims have been publicly named, but it has been observed in large-scale malspam campaigns. No law enforcement actions have been reported as of March 2025.
🔍 Detection Indicators
Known file hashes include SHA256 8a4c9b1e2f3d4c5b6a7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9 (sample from Zscaler report). Behavioral indicators include the creation of a scheduled task named “FabookieUpdateTask”, the presence of the registry key HKCU...RunFabookieUpdater, and outbound HTTPS POST requests to hxxps://fabookie[.]xyz/api/collect. The malware writes stolen data to %TEMP%fabook_data.log before exfiltration.
☠️ Risk & Impact
Fabookie primarily causes credential theft and cryptocurrency wallet compromise, leading to financial losses for individual victims and potential account takeovers. Zscaler reported that the malware exfiltrates saved passwords, cookies, and crypto wallet files, directly impacting personal banking and digital asset security. The stealer has been observed targeting users in the finance and e-commerce sectors via phishing lures.
🛡️ Mitigation
Defenders should block the C2 domain fabookie[.]xyz and associated IPs, deploy YARA rules matching the FabookieUpdateTask mutex name “FabookMutex”, and ensure email gateways filter Excel attachments exploiting CVE-2017-0199. Endpoint detection rules should monitor for process hollowing into svchost.exe and scheduled task creation with the Fabookie naming convention.
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.