NodeStealer is an infostealer associated with campaigns focused on hijacking Facebook and Meta business assets, particularly Facebook Business Manager and Ads Manager accounts. It was initially observed as a JavaScript or Node.js-based stealer and later evolved into Python-based variants with broader collection and account-takeover functionality. Reporting has linked NodeStealer activity to likely Vietnam-based operators, based on language artifacts, targeting patterns, and overlap with other Vietnam-associated stealer ecosystems such as DuckTail, VietCredCare, and PXA Stealer.
NodeStealer is designed to harvest sensitive browser-resident data and business-account information. Documented capabilities include theft of browser credentials and cookies, extraction of Facebook access tokens and business account metadata, collection of advertising-related account details, and theft of cryptocurrency wallet data including MetaMask. Some variants also targeted stored payment-card information in browsers. Exfiltration has been observed via command-and-control infrastructure and Telegram.
More advanced Python variants expanded beyond simple theft into account takeover operations. Observed functionality included checking whether victims were logged into Facebook business services, querying Facebook APIs for business-account details, and attempting to change account email ownership by automating mailbox acquisition and verification workflows. Certain variants also included anti-analysis and anti-virtual-machine checks.
NodeStealer has been delivered through phishing and spearphishing campaigns using business-themed lures, including copyright-related notices and offers of business materials. Victims were directed to download archive files containing malicious executables. Additional delivery chains have used DLL sideloading through legitimate applications to launch the malware. In some campaigns, NodeStealer also acted as a staging component for further compromise by downloading additional malware, disabling security controls, and establishing persistence.
The malware primarily targets Windows systems and focuses on organizations and individuals with monetizable social-media advertising access, including businesses, marketing operations, and other entities managing Facebook advertising resources. Its evolution from credential theft toward direct business-account takeover reflects the growing criminal market for stolen advertising accounts and related digital assets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Ad account theft, the systematic hijacking of Meta Business Manager and Google Ads accounts, has grown into a commodity-driven cybercrime economy... Legitimate ad spend history raises account trust scores, meaning aged, active accounts can serve ads that pass platform safety checks that would reject a new attacker-created account.
The main infection vector for the infostealer was a phishing campaign... The threat actor used multiple Facebook pages and users to post information luring victims to download a link from known cloud file storage providers. After clicking on it, a .zip file was downloaded to the machine, containing the malicious infostealer executable.
The infection chain starts with a spear-phishing email with a malicious embedded link, which upon clicking, downloads and installs the malware under the guise of a legitimate application.
Threat actors have moved away from purpose-built malicious infrastructure and toward legitimate, high-reputation sending platforms that email security tools are configured to trust. Mimecast’s telemetry shows that among these campaigns, about one in three detections arrived through Salesforce infrastructure, with another quarter delivered through Google Workspace mail-merge tools and SharePoint-hosted links.
attackers attempt to bypass User Account Control (UAC) and execute the PowerShell scripts used to download the above-mentioned zip files.
As shown in Figure 4, the sideloaded DLL then executes a batch file, images\active-license.bat, using the command prompt (cmd.exe).
Contains a portable Python 3.10 interpreter that will download and execute the final payload... The file entry.txt contains an obfuscated Python script.
Ad account theft, the systematic hijacking of Meta Business Manager and Google Ads accounts, has grown into a commodity-driven cybercrime economy... Legitimate ad spend history raises account trust scores, meaning aged, active accounts can serve ads that pass platform safety checks that would reject a new attacker-created account.
Ad account theft, the systematic hijacking of Meta Business Manager and Google Ads accounts, has grown into a commodity-driven cybercrime economy... Legitimate ad spend history raises account trust scores, meaning aged, active accounts can serve ads that pass platform safety checks that would reject a new attacker-created account.
the malware modifies the account email address for the Facebook business account of the victim... If successful, the attackers have now taken over the Facebook account by replacing the legitimate user’s email address with a mailbox under their control.
This batch file images\active-license.bat contains a malicious encoded command... The file entry.txt contains an obfuscated Python script... The script uses the combination of native Python commands exec() and marshal.loads() to execute Python bytecode directly.
The executable file Nombor Rekod 052881.exe, which appears to be a PDF reader – normally recognized as a trusted application – was observed being exploited to sideload the malicious DLL file oledlg.dll.
The malware then exfiltrates the output files through Telegram and deletes the files to remove its tracks
Ad account theft, the systematic hijacking of Meta Business Manager and Google Ads accounts, has grown into a commodity-driven cybercrime economy... Legitimate ad spend history raises account trust scores, meaning aged, active accounts can serve ads that pass platform safety checks that would reject a new attacker-created account.
NodeStealer allowed threat actors to steal browser cookies to hijack accounts on the platform, specifically aiming toward business accounts.
21 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Vietnam-linked malware family associated with theft of Meta Business Manager and Google Ads accounts.
NodeStealer 2.0 – The Python Version: Stealing Facebook Business Accounts BitRAT NodeStealer XWorm
Referenced as another Vietnamese-attributed stealer with similarities to the analyzed campaign.
Information-stealing malware referenced as a prior payload delivered via HaiHaiSoft PDF Reader DLL side-loading abuse.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.