Hackers are using Facebook ads to infect Windows PCs with password-stealing malware — how to stay safe

Facebook app on phone
(Image credit: Shutterstock)

You wouldn’t expect to run into password-stealing malware while browsing Facebook but hackers are now using fake ads to target vulnerable Windows PCs on the popular social network.

As reported by BleepingComputer, security researchers at Trustwave have discovered several new campaigns that use fake Windows themes along with fake downloads for pirated games and software as a lure to trick unsuspecting Facebook users into clicking on their malicious ads. This is done by either creating new Facebook business accounts or by hijacking existing ones.

Here’s everything you need to know about this new campaign and how you can keep your own Windows PC safe from malware.

Stealing passwords and Facebook account info

A hacker typing quickly on a keyboard

(Image credit: Shutterstock)

According to Trustwave’s report, the hackers behind this latest round of attacks have taken out thousands of ads for each individual campaign. For instance, the top campaign called “blue-softs” had 8,100 ads while “xtaskbar-themes” had 4,300 ads.

Clicking on one of these fake ads takes potential victims to malicious sites hosted on Google Sites or True Hosting which appear to be download pages for the themes or software advertised on Facebook. These sites have a download button that when clicked, downloads a ZIP file with a name that matches the product advertised online.

As you’d expect, these ZIP files actually contain the SYS01 info-stealing malware which was first discovered by the cybersecurity firm Morphisec back in 2022. The malware itself uses a collection of executables, dynamic-link library (DLL) files, PowerShell scripts and PHP scripts to install itself and steal data from a targeted Windows PC.

SYS01 can steal cookies from your browser along with any passwords stored there and a victim’s browsing history. However, it also includes a task that leverages Facebook cookies on an infected device to extract data from a victim’s profile including their name, email, birthday and more on the social network. 

Even if you’re not on Facebook, you still need to be careful as Trustwave has observed similar malvertising campaigns on both YouTube and LinkedIn.

How to stay safe from malware

A woman looking at a smartphone while using a laptop

(Image credit: Shutterstock)

To avoid falling victim to this campaign and others like it, the first and most important thing you can do is to avoid clicking on ads. 

Hackers can buy ad space just as easily as legitimate businesses, so to stay safe, you’re better off not clicking on ads at all. In fact, even the FBI recommends you now use an ad-blocker

If you do see an ad for something you like, though, you’re better off heading to a search engine or — better yet — to the company’s site directly and shopping for the item you may be interested in. When you do need to interact with an ad online, you’re going to want to make sure that you’re using the best antivirus software to protect yourself from any malware or other viruses that ad could be spreading.

We’ve now seen fake ads on both Google and Facebook, and both companies are trying to crack down on this practice. In the meantime, you just need to be careful where you click and avoid downloading anything from unknown sites and sources online.

More from Tom's Guide

Network
Arrow
Intego
Norton
Contract Length
Arrow
Showing 2 of 2 deals
Filters
Arrow
TOPICS
Anthony Spadafora
Managing Editor Security and Home Office

Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches to password managers and the best way to cover your whole home or business with Wi-Fi. He also reviews standing desks, office chairs and other home office accessories with a penchant for building desk setups. Before joining the team, Anthony wrote for ITProPortal while living in Korea and later for TechRadar Pro after moving back to the US. Based in Houston, Texas, when he’s not writing Anthony can be found tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
A hacker typing quickly on a keyboard
Hackers are posing as Apple and Google to infect Macs with malware — don’t fall for these fake browser updates
A laptop displaying the Chrome logo
Don't click this — malicious ads impersonating Google Chrome spreading dangerous malware
A hacker typing quickly on a keyboard
Thousands of WordPress sites hijacked to spread Windows and Mac malware - how to stay safe
Reddit logo and Reddit logo on phone
Hackers have created hundreds of fake Reddit sites to spread info-stealing malware
Green skull on smartphone screen.
Malicious Android apps with 60 million installs bombarding phones with ads and phishing attacks — how to stay safe
An FBI agent typing on a computer
FBI issues warning to millions of Americans to avoid these websites that can steal your passwords and banking info
Latest in Malware & Adware
Green skull on smartphone screen.
Malicious Android apps with 60 million installs bombarding phones with ads and phishing attacks — how to stay safe
Malware
Dangerous new password-stealing trojan automatically reinstalls itself on infected PCs
An FBI agent typing on a computer
FBI issues warning to millions of Americans to avoid these websites that can steal your passwords and banking info
A hacker typing quickly on a keyboard
New MassJacker malware is hijacking digital wallets to steal large sums from users
A person trying to set up a new Wi-Fi router
Thousands of TP-Link routers have been infected by a botnet to spread malware
A smartphone screen displaying the Android name and logo next to a sign reading 'MALWARE'.
Fake Google Play Store pages are spreading Trojan malware that can steal your financial data
Latest in News
Apple Watch Series 10
Future Apple Watch models could get a surprising new feature — what we know
NYTimes Connections
NYT Connections today hints and answers — Monday, March 24 (#652)
NYT Strands on a cellphone
NYT Strands today — hints, spangram and answers for game #386 (Monday, March 24 2025)
iPhone 16 Pro vs iPhone 16 Pro Max in hand showing displays
Forget iPhone 17 — iPhone 18 could get this huge upgrade
The new Husqvarna iQ series robot lawn mower.
Husqvarna’s new robot mowers offer GPS for less
Rendered images of rumored foldable iPhone.
Foldable iPhone report just revealed key details — here's what we know