New version of NodeStealer malware steals Facebook passwords, records keystrokes, and takes screenshots
Read more
Olhar Digital
olhardigital.com.br

New version of NodeStealer malware steals Facebook passwords, records keystrokes, and takes screenshots

Netskope Threat Labs identified a new variation of the Python NodeStealer, which has significantly expanded its ability to collect data related to Facebook, now gathering information about account administrators.

In addition to stealing credentials, the malware records everything typed by the user, monitors the clipboard, and takes screenshots. The collected information is transmitted through two bots operating on Telegram.

One of these bots is responsible for receiving credentials, passwords, and cookies saved in browsers, while the other focuses on data extracted specifically from Facebook. The threat also seeks Wi-Fi passwords, files located in the images folder, and data stored in two other distinct browsers.

With these enhanced functionalities, NodeStealer has taken on characteristics of spyware, a type of malicious software designed to monitor actions on a device and collect data without user consent.

Potential development with the aid of Artificial Intelligence

The investigation conducted by Netskope Threat Labs also pointed to evidence that the malware's new features may have been created with the support of artificial intelligence (AI). Observed signs include the recurrent use of emojis in program logs and the presence of similarly structured code calls, characteristics absent in previous samples of NodeStealer.

Researchers consider these elements consistent with code generated with the assistance of language models. Affected victims were mainly located in Asia and North America, with attacks hitting various sectors, showing higher incidence in the financial services segment.

Claudio Bannwart, Netskope's country manager in Brazil, warned that the potential reach of this threat requires attention from both Brazilian users and companies. He emphasized that this type of risk can impact accounts globally, recommending that users employ multi-factor authentication, verify active access, and monitor unknown activities. For corporations, it is crucial to define who has administrative permissions and to supervise the use of these accounts, as greater access to resources and data requires greater control.

A detailed analysis of this new version of Python NodeStealer is available at Netskope Threat Labs. The original article was initially published in Olhar Digital.

Popular