A Vietnamese threat actor has been linked to a “malverposting” campaign that has infected over 500,000 devices worldwide in the past three months. Malverposting involves using promoted social media posts on platforms like Facebook and Twitter to distribute malicious software.
Guardio Labs revealed that the attacker creates new business profiles and hijacks popular accounts to serve ads offering free adult rated photo album downloads. The downloaded ZIP archives contain executable files that, when clicked, deploy stealer malware to harvest session cookies, account data, and other information.
The stolen information is then used to create hijacked Facebook bot accounts that push more sponsored posts, expanding the scheme. Most infections have been reported in Australia, Canada, India, the UK and the US.
The attacker constantly refines their tactics and introduces new evasive techniques to avoid detection.