
"Facebook Ads Spreading Ov3r_Stealer Malware to Steal Crypto and Credentials"
A new password-stealing malware called Ov3r_Stealer is being spread through fake job ads on Facebook, leading users to a Discord URL where a PowerShell script downloads the malware payload from a GitHub repository. The malware, discovered by Trustwave, targets a wide range of apps and attempts to steal account credentials and cryptocurrency. It establishes persistence on infected computers and sends stolen data to a Telegram bot every 90 minutes. Trustwave has found links between the malware and specific usernames in software cracking forums and notes code similarities with another stealer, Phemedrone. The nationality of the threat actor behind Ov3r_Stealer remains inconclusive.
