NodeStealer is a Python-based information stealer and spyware family, first identified in 2023, that targets Windows users’ browser data, Facebook accounts, Facebook Business and Ads Manager assets, payment-card data, and cryptocurrency-wallet information. Earlier variants included JavaScript-based implementations, while later variants use Python and have expanded from browser and Facebook credential theft into persistent surveillance. Recent versions collect browser passwords, cookies, session data, Facebook identity and business information, advertising assets, account-security information, Wi-Fi passwords, and files from user directories. They can query numerous Facebook Graph API endpoints to harvest personal, social-graph, business, commerce, advertising, integration, and login-related data.
NodeStealer variants support keylogging, clipboard monitoring, and screenshot capture, and exfiltrate collected information through Telegram-based command-and-control infrastructure. Some versions separate general browser-data collection from Facebook-specific exfiltration through distinct Telegram bots. Historical variants established Windows persistence, attempted to disable Microsoft Defender, used a UAC-bypass technique to execute follow-on payloads, and delivered additional remote-access malware. The family has also incorporated anti-analysis measures, including virtual-machine checks and modified Python-bytecode metadata intended to complicate timeline analysis and automated inspection.
Observed delivery chains include spear-phishing messages carrying malicious archives, social-media lures promoting business-related materials, and DLL sideloading through trojanized PDF-reader packages. Activity has affected organizations in Asia and North America, with financial services prominently represented among recent victims; a separate campaign targeted an educational institution in Malaysia. Multiple assessments have linked NodeStealer operations to Vietnamese threat actors or the Vietnam-associated ad-account-theft ecosystem, based on code artifacts, targeted browser selection, and operational infrastructure. Stolen Facebook business and advertising accounts can be abused for unauthorized advertising, advertising-budget theft, impersonation, social engineering, and follow-on account takeover.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
Ad account theft, the systematic hijacking of Meta Business Manager and Google Ads accounts, has grown into a commodity-driven cybercrime economy... Legitimate ad spend history raises account trust scores, meaning aged, active accounts can serve ads that pass platform safety checks that would reject a new attacker-created account.
The main infection vector for the infostealer was a phishing campaign... The threat actor used multiple Facebook pages and users to post information luring victims to download a link from known cloud file storage providers. After clicking on it, a .zip file was downloaded to the machine, containing the malicious infostealer executable.
Threat actors have moved away from purpose-built malicious infrastructure and toward legitimate, high-reputation sending platforms that email security tools are configured to trust. Mimecast’s telemetry shows that among these campaigns, about one in three detections arrived through Salesforce infrastructure, with another quarter delivered through Google Workspace mail-merge tools and SharePoint-hosted links.
Ad account theft, the systematic hijacking of Meta Business Manager and Google Ads accounts, has grown into a commodity-driven cybercrime economy... Legitimate ad spend history raises account trust scores, meaning aged, active accounts can serve ads that pass platform safety checks that would reject a new attacker-created account.
Ad account theft, the systematic hijacking of Meta Business Manager and Google Ads accounts, has grown into a commodity-driven cybercrime economy... Legitimate ad spend history raises account trust scores, meaning aged, active accounts can serve ads that pass platform safety checks that would reject a new attacker-created account.
the malware modifies the account email address for the Facebook business account of the victim... If successful, the attackers have now taken over the Facebook account by replacing the legitimate user’s email address with a mailbox under their control.
“The malware is also distributed as compiled Python bytecode with altered header fields, apparently intended to obscure its compilation timeline and possibly interfere with automated analysis.”
The malware then exfiltrates the output files through Telegram and deletes the files to remove its tracks
“It saves captured text in a temporary file, sends it to the primary Telegram command-and-control channel every 120 seconds, and then clears the file’s contents.”
Ad account theft, the systematic hijacking of Meta Business Manager and Google Ads accounts, has grown into a commodity-driven cybercrime economy... Legitimate ad spend history raises account trust scores, meaning aged, active accounts can serve ads that pass platform safety checks that would reject a new attacker-created account.
The latest variant uses the Python ecosystem and incorporates libraries and functionality for: Keyboard monitoring.
The latest variant uses the Python ecosystem and incorporates libraries and functionality for: Browser session/cookie theft.
The latest variant uses the Python ecosystem and incorporates libraries and functionality for: Wi-Fi password collection.
it checks for Facebook users and passwords within the cookies and local databases of the following browsers: Chrome, Edge, Cốc Cốc, Brave and Firefox.
The latest variant uses the Python ecosystem and incorporates libraries and functionality for: File collection from the victim's Pictures directory.
The latest variant uses the Python ecosystem and incorporates libraries and functionality for: Keyboard monitoring.
“It saves captured text in a temporary file, sends it to the primary Telegram command-and-control channel every 120 seconds, and then clears the file’s contents.”
“It saves captured text in a temporary file, sends it to the primary Telegram command-and-control channel every 120 seconds, and then clears the file’s contents.”
The latest variant uses the Python ecosystem and incorporates libraries and functionality for: Screenshot capture.
the malware has a function that parses emails, so it can read the victim’s emails.
21 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Python-based information stealer first tracked in 2023. It steals browser credentials, passwords, cookies, Facebook and Facebook Ads Manager data, and payment-card information. The upgraded variant adds persistent keystroke logging, clipboard monitoring, and screenshot capture, exfiltrating collected data through Telegram command-and-control bots.
Python-based information stealer first tracked in 2023 that steals browser credentials, passwords, cookie databases, Facebook and Facebook Ads Manager data, and payment-card information. The upgraded August 2026 variant adds persistent keylogging, clipboard monitoring, and screenshot capture, exfiltrating stolen material through Telegram command-and-control bots.
Python-based infostealer and spyware that steals browser credentials, passwords, cookies, Facebook and Facebook Ads Manager data, credit-card information, Wi-Fi passwords, and the victim's Pictures folder. The latest variant persistently logs keystrokes, monitors clipboard contents, captures screenshots, extensively harvests Facebook Graph API data, and exfiltrates stolen data through separate Telegram bot C2 channels for general stolen data and Facebook-specific data.
Vietnam-linked malware family associated with theft of Meta Business Manager and Google Ads accounts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.