Skip to main content

Kaspersky warns of a new credential-stealing campaign via Facebook

September 4, 2025

Since late August 2025, the Kaspersky Global Research and Analysis Team (GReAT) has been observing a new malicious campaign leveraging a stealer — a type of malware designed to steal passwords and other account information. The StealC v2 infostealer is likely being spread through Facebook messages. More than 400 incidents have been identified to date, targeting users across multiple countries, including confirmed cases in Jordan, Yemen, Qatar, and Lebanon.

Facebook users receive messages likely containing a link disguised as a notification that their account has been blocked as part of this attack.

A phishing message with a button that downloads the info-stealer when clicked

An example of a phishing message disguised as an account block notification

Clicking the link opens a fake support page claiming that the user’s account has been blocked due to suspicious activity. To “restore access,” users are prompted to use the “Appeal” button, which initiates the download of a malicious script that installs the StealC v2, a dangerous malware offered under a Malware-as-a-Service model, on the victim’s device. The malware itself steals passwords, cookies, screenshots, as well as cryptocurrency wallet data.

After clicking on the link in the emailA phishing message with a button that downloads the info-stealer when clicked

“Cybercriminals often exploit users’ fear of losing account access and a perceived sense of urgency. This pressure can lead individuals to act without caution, increasing the risk of infection by malware such as StealC v2. Users should remain vigilant and always verify the authenticity of messages before clicking any links,” comments Marc Rivero, lead security researcher at Kaspersky's Global Research and Analysis Team. 

StealC v2, first observed in 2025, significantly enhances the malware’s capabilities and elevates the risk to both individual and corporate users. The original StealC, which emerged in 2023 on dark web platforms, quickly became a sought-after tool among cybercriminals thanks to its accessibility, capabilities and ease of access.

To be protected from phishing, Kaspersky recommends corporate and individual users:

  • Sometimes emails and websites look just like real ones. It depends on how well the criminals did their homework. But the hyperlinks, most likely, will be incorrect, with spelling mistakes, or they can redirect you to a different place.
  • Look for urgency or threats. Phishing attempts frequently try to create a sense of urgency or fear. Be cautious of emails demanding immediate action, such as changing a password or providing personal information.
  • Verify unsolicited messages, calls, or links, even if they appear legitimate. Never share 2FA codes. 
  • Use Kaspersky Next (in corporate environments) or Kaspersky Premium (for individual use) to block phishing attempts.

 

Kaspersky warns of a new credential-stealing campaign via Facebook

Since late August 2025, the Kaspersky Global Research and Analysis Team (GReAT) has been observing a new malicious campaign leveraging a stealer — a type of malware designed to steal passwords and other account information. The StealC v2 infostealer is likely being spread through Facebook messages. More than 400 incidents have been identified to date, targeting users across multiple countries, including confirmed cases in Jordan, Yemen, Qatar, and Lebanon.
Kaspersky logo

About Kaspersky

Kaspersky is a global cybersecurity and digital privacy company founded in 1997. With over a billion devices protected to date from emerging cyberthreats and targeted attacks, Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services to protect individuals, businesses, critical infrastructure, and governments around the globe. The company’s comprehensive security portfolio includes leading digital life protection for personal devices, specialized security products and services for companies, as well as Cyber Immune solutions to fight sophisticated and evolving digital threats. We help millions of individuals and nearly 200,000 corporate clients protect what matters most to them. Learn more at www.kaspersky.com.

Related Articles Press Releases