• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
new 'vietcredcare' stealer targeting facebook advertisers in vietnam

New ‘VietCredCare’ Stealer Targeting Facebook Advertisers in Vietnam

You are here: Home / General Cyber Security News / New ‘VietCredCare’ Stealer Targeting Facebook Advertisers in Vietnam
February 21, 2024

Fb advertisers in Vietnam are the target of a previously unfamiliar information and facts stealer dubbed VietCredCare at minimum due to the fact August 2022.

The malware is “noteworthy for its ability to automatically filter out Facebook session cookies and qualifications stolen from compromised products, and evaluate whether these accounts handle company profiles and if they preserve a optimistic Meta advertisement credit stability,” Singapore-headquartered Team-IB explained in a new report shared with The Hacker Information.

The conclusion purpose of the big-scale malware distribution plan is to facilitate the takeover of corporate Facebook accounts by focusing on Vietnamese people who deal with the Fb profiles of prominent firms and businesses.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


Fb accounts that have been productively seized are then employed by the threat actors powering the operation to publish political written content or to propagate phishing and affiliate scams for monetary obtain.

Cybersecurity

VietCredCare is presented to other aspiring cybercriminals beneath the stealer-as-a-support model and advertised on Facebook, YouTube, and Telegram. It is really assessed to be managed by Vietnamese-speaking men and women.

Customers possibly have the selection of obtaining obtain to a botnet managed by the malware’s builders, or procure entry to the supply code for resale or personal use. They are also presented a bespoke Telegram bot to handle the exfiltration and shipping of qualifications from an infected product.

The .NET-based mostly malware is distributed by way of hyperlinks to bogus websites on social media posts and prompt messaging platforms, masquerading as legitimate software program like Microsoft Business or Acrobat Reader to dupe visitors into installing them.

VietCredCare Stealer

One particular of its main promoting factors is its ability to extract qualifications, cookies, and session IDs from web browsers like Google Chrome, Microsoft Edge, and Cốc Cốc, indicating its Vietnamese concentrate.

It can also retrieve a victim’s IP handle, test if a Facebook is a company profile, and evaluate no matter whether the account in dilemma is currently taking care of any adverts, even though simultaneously taking actions to evade detection by disabling the Windows Antimalware Scan Interface (AMSI) and introducing alone to the exclusion record of Windows Defender Antivirus.

“VietCredCare’s core functionality to filter out Fb qualifications puts corporations in equally the public and private sectors at risk of reputational and economic damages if their sensitive accounts are compromised,” Vesta Matveeva, head of the Significant-Tech Crime Investigation Office for APAC, stated.

Cybersecurity

Credentials belonging to various govt agencies, universities, e-commerce platforms, financial institutions, and Vietnamese organizations have been siphoned by using the stealer malware.

VietCredCare is also the latest addition to a prolonged record of stealer malware, such as Ducktail and NodeStealer,that has originated from the Vietnamese cyber felony ecosystem with the intent of concentrating on Facebook accounts.

“The stealer-as-a-company organization model permits threat actors with little to no technological techniques to enter the cybercrime area, which effects in extra harmless victims remaining harmed,” Group-IB mentioned.

Observed this post intriguing? Stick to us on Twitter  and LinkedIn to read a lot more special content we put up.


Some sections of this write-up are sourced from:
thehackernews.com

Previous Post: «signal introduces usernames, allowing users to keep their phone numbers Signal Introduces Usernames, Allowing Users to Keep Their Phone Numbers Private
Next Post: Cybersecurity for Healthcare—Diagnosing the Threat Landscape and Prescribing Solutions for Recovery cybersecurity for healthcare—diagnosing the threat landscape and prescribing solutions for»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.