NSFW Facebook ads being used to spread dangerous malware — don’t click on these

Facebook logo on iPhone
(Image credit: Shutterstock)

Hackers have devised a clever new way to trick unsuspecting Facebook users into downloading malware on their computers.

While having your Facebook hacked is bad enough as it is, a new campaign discovered by Bitdefender uses compromised Facebook Business accounts to deliver the NodeStealer malware. 

Just like with other info-stealing malware, NodeStealer targets Windows PCs with the goal of stealing browser cookies as well as saved usernames and passwords which can then be used to compromise a user’s other online accounts. 

According to a blog post from Meta’s engineering team, previous NodeStealer campaigns have used malicious documents to distribute this dangerous malware. However, this time around, hackers are now using malicious ads to do so. 

Here’s everything you need to know about this latest NodeStealer campaign and why you might want to think twice before clicking on any ads you see online.

Duping Facebook users with fake photo albums

A hacker typing quickly on a keyboard

(Image credit: Shutterstock)

During its investigation into this new NodeStealer campaign, Bitdefender found that the hackers behind it have come up with an interesting way to get potential victims to click on their malicious ads.

In a blog post detailing its findings, the firm’s security researchers explained that NSFW ads are the main lure used in this campaign. These ads are for Facebook pages which feature scantily clad women as male users are the targeted demographic.

Bitdefender found a number of fake Facebook profiles using “Album Update”, “Album Girl News Update”, “Private Album Update”, “Hot Album Update Today” or other similar names. These profiles feature one or two photos of young women where their faces or NSFW outfits are censored.

Once these fake profiles are set up, the hackers then begin running ads on Facebook to promote their content with short descriptions like “New stuff is online today” or “Watch now before it’s deleted” to instill a sense of urgency and get unsuspecting users to click on them. 

When a potential victim does click on one of these ads, instead of getting access to an album full of NSFW photos, they instead download a Windows executable. While most people know the dangers of running a “.exe” file downloaded from an untrusted source online, many don’t and the hackers are counting on this.

Instead of a NSFW photo album, the executable installs the NodeStealer malware on their computer and then proceeds to steal any passwords or cookies stored on the device. 

How to stay safe from malware delivered via ads

With this campaign in particular, the victims should have recognized the dangers of downloading NSFW photos from a suspicious-looking Facebook profile they saw in an advertisement. However, there are many other similar campaigns that use malicious ads for legitimate products to infect unsuspecting users with malware.

This is why you always want to be careful when clicking on ads online. Besides on Facebook, malicious ads have also started to appear on Google Search which is why you’re better off avoiding ads altogether. Instead, if you see a deal on a product you’re interested in an ad on a social network or even in a search engine, you’re better off navigating to the retailer’s webpage yourself and manually searching for it.

At the same time, you also want to be using the best antivirus software on your PC, the best Mac antivirus software on your Mac or one of the best Android antivirus apps on your Android smartphone to protect yourself from malware. Likewise, if you’re really worried about hackers, it may also be worth investing in one of the best identity theft protection services as they can help you deal with fraud and getting your identity back if it’s stolen online.

With Black Friday just around the corner, you can bet that hackers are going to capitalize on all of the extra holiday shopping with even more malicious ads. For this reason, you’re better off getting help finding deals from Tom’s Guide or other trusted news sites.

More from Tom's Guide

Anthony Spadafora
Managing Editor Security and Home Office

Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches to password managers and the best way to cover your whole home or business with Wi-Fi. He also reviews standing desks, office chairs and other home office accessories with a penchant for building desk setups. Before joining the team, Anthony wrote for ITProPortal while living in Korea and later for TechRadar Pro after moving back to the US. Based in Houston, Texas, when he’s not writing Anthony can be found tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
A laptop displaying the Chrome logo
Don't click this — malicious ads impersonating Google Chrome spreading dangerous malware
A hacker typing quickly on a keyboard
Hackers are posing as Apple and Google to infect Macs with malware — don’t fall for these fake browser updates
Green skull on smartphone screen.
Malicious Android apps with 60 million installs bombarding phones with ads and phishing attacks — how to stay safe
An FBI agent typing on a computer
FBI issues warning to millions of Americans to avoid these websites that can steal your passwords and banking info
Reddit logo and Reddit logo on phone
Hackers have created hundreds of fake Reddit sites to spread info-stealing malware
A hacker typing quickly on a keyboard
Thousands of WordPress sites hijacked to spread Windows and Mac malware - how to stay safe
Latest in Social Media
Elon Musk next to the X logo for the social media network that used to be called Twitter
X was down — live updates on outage Musk blames on ‘massive cyberattack’
Bluesky logo with X logo in the background
Flashes is a brand new Instagram alternative — and it’s basically Bluesky for images
Instagram app on iPhone
Instagram was down — live updates on the quick outage
elon musk in front of image of earth from space
Elon Musk reportedly exploring buying TikTok — Bytedance says 'pure fiction'
Instagram logo on iPhone with Instagram website in background.
Instagram now lets you schedule DMs — here's how to do it
TikTok displayed on a smart phone with a USA flag in the background
Google and Apple warned by Congress to be ready to remove TikTok from app stores — here's the date
Latest in News
iPhone 16 Pro vs iPhone 16 Pro Max in hand showing displays
Forget iPhone 17 — iPhone 18 could get this huge upgrade
The new Husqvarna iQ series robot lawn mower.
Husqvarna’s new robot mowers offer GPS for less
Rendered images of rumored foldable iPhone.
Foldable iPhone report just revealed key details — here's what we know
NYTimes Connections
NYT Connections today hints and answers — Sunday, March 23 (#651)
NYT Strands on a cellphone
NYT Strands today — hints, spangram and answers for game #385 (Sunday, March 23 2025)
Nintendo Switch 2
Nintendo Switch 2 rumored specs — here’s what we know so far