FaceStealer is a Python-based information stealer first documented in July 2021 by Zscaler ThreatLabz, targeting Facebook business and advertising accounts. Operated by an unknown threat actor, it belongs to the stealer category and specifically harvests Facebook session cookies and credentials to hijack accounts for fraudulent ad campaigns.
FaceStealer propagates through malicious browser extensions (Chrome and Edge) and spear-phishing emails with weaponized documents that drop a Python script. The malware uses a Telegram bot for command-and-control (C2) exfiltration, sending stolen cookies and login tokens to a Telegram channel. It achieves persistence by adding a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun and employs basic anti-debugging techniques such as checking for sandbox environments. The stealer also targets stored browser credentials from Chromium-based browsers and can bypass two-factor authentication by stealing session tokens. No exploit of public CVEs has been reported; instead it relies on social engineering to gain initial access.
First observed in campaigns against marketing agencies and small businesses in Southeast Asia and Latin America in late 2021, FaceStealer was later used in a high‑profile incident targeting a US-based digital marketing firm in early 2022. The malware has been linked to the theft of over $1.5 million in fraudulent Facebook ad spend. No law enforcement actions have been publicly associated with FaceStealer as of 2024.
Known SHA‑256 hash of an early sample: a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2 (reported by Zscaler). Behavioral indicators include outbound HTTP POST requests to Telegram API endpoint api.telegram.org/bot
FaceStealer causes unauthorized access to Facebook Business Manager accounts, enabling attackers to run fraudulent ads that generate affiliate revenue or spread malware. Financial losses for affected businesses range from $5,000 to over $500,000 per incident, disproportionately impacting small-to-medium enterprises (SMEs) in the digital marketing sector. Data exfiltration includes full browser cookie stores, which can be replayed to hijack other online services.
Organizations should enforce Multi‑Factor Authentication (MFA) on all social media accounts, block Telegram API domains at the network gateway, and deploy EDR solutions with behavioral rules detecting suspicious POST requests to Telegram endpoints. Regular user awareness training against spear‑phishing and fake browser extensions is critical.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.