loader image
Socelars Steals Facebook Ad Sessions on Windows

A stealthy malware known as Socelars steals Facebook Ad session data and other sensitive information from infected Windows systems, according to cybersecurity researchers. The spyware disguises itself as legitimate software, installs silently, and targets browser-stored session cookies—particularly from platforms like Facebook and Amazon.

Once active, Socelars executes a three-stage attack. It first collects system details and elevates privileges using COM auto-elevation. It then harvests session cookies from Google Chrome and Mozilla Firefox, enabling attackers to bypass password and multi-factor authentication protections. Finally, it exfiltrates the data to attacker-controlled servers.

Businesses reliant on digital advertising and e-commerce face heightened risks. Compromised Facebook Ads Manager accounts allow attackers to hijack campaigns, drain budgets, and resell access. Security experts warn that digital agencies managing multiple accounts are especially vulnerable.

Organizations can mitigate threats by deploying hardware authentication keys, clearing browser cookies regularly, and monitoring malware infrastructure. Cybercriminals continue leveraging Socelars as it efficiently steals Facebook Ad session access.

Socelars Malware Attacking Windows Systems to Steal Sensitive Business Data

Write a Reply or Comment

Your email address will not be published. Required fields are marked *