Skip to main content

Boteraser | Website and Server Security Solutions

FaceStealer

Stealer

⚠️ Overview

FaceStealer is a Python-based information stealer first documented in July 2021 by Zscaler ThreatLabz, targeting Facebook business and advertising accounts. Operated by an unknown threat actor, it belongs to the stealer category and specifically harvests Facebook session cookies and credentials to hijack accounts for fraudulent ad campaigns.

🔧 Technical Capabilities

FaceStealer propagates through malicious browser extensions (Chrome and Edge) and spear-phishing emails with weaponized documents that drop a Python script. The malware uses a Telegram bot for command-and-control (C2) exfiltration, sending stolen cookies and login tokens to a Telegram channel. It achieves persistence by adding a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun and employs basic anti-debugging techniques such as checking for sandbox environments. The stealer also targets stored browser credentials from Chromium-based browsers and can bypass two-factor authentication by stealing session tokens. No exploit of public CVEs has been reported; instead it relies on social engineering to gain initial access.

📜 History & Notable Incidents

First observed in campaigns against marketing agencies and small businesses in Southeast Asia and Latin America in late 2021, FaceStealer was later used in a high‑profile incident targeting a US-based digital marketing firm in early 2022. The malware has been linked to the theft of over $1.5 million in fraudulent Facebook ad spend. No law enforcement actions have been publicly associated with FaceStealer as of 2024.

🔍 Detection Indicators

Known SHA‑256 hash of an early sample: a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2 (reported by Zscaler). Behavioral indicators include outbound HTTP POST requests to Telegram API endpoint api.telegram.org/bot/sendDocument with Base64‑encoded cookie data. Registry key FaceStealerUpdate under Run is a persistence marker. The malware uses a User‑Agent string mimicking Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36.

☠️ Risk & Impact

FaceStealer causes unauthorized access to Facebook Business Manager accounts, enabling attackers to run fraudulent ads that generate affiliate revenue or spread malware. Financial losses for affected businesses range from $5,000 to over $500,000 per incident, disproportionately impacting small-to-medium enterprises (SMEs) in the digital marketing sector. Data exfiltration includes full browser cookie stores, which can be replayed to hijack other online services.

🛡️ Mitigation

Organizations should enforce Multi‑Factor Authentication (MFA) on all social media accounts, block Telegram API domains at the network gateway, and deploy EDR solutions with behavioral rules detecting suspicious POST requests to Telegram endpoints. Regular user awareness training against spear‑phishing and fake browser extensions is critical.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.