Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
SilentFade could determine accounts that already had linked payment methods, so that attackers could run ads and pay for them using the account owner’s payment method.
SilentFade could determine accounts that already had linked payment methods, so that attackers could run ads and pay for them using the account owner’s payment method.
The cloaking service would decide whether to send a user to the malicious page or an innocuous one based on the geolocated IP address of the user clicking on the ad, the presence of the correct HTTP Referer header, and other features.
Since then, SilentFade has resorted to using string obfuscation to make it more difficult to hunt for malware samples and to complicate AV detection signatures.
The service is responsible for persistence across reboots and for dropping 32-bit and 64-bit version DLLs (usually as winhttp.dll or winmm.dll) in Chrome’s application directory.
With these changes, SilentFade minimized the likelihood of users noticing unrecognized activity on their accounts – preserving undetected access to compromised accounts for longer.
SilentFade could determine accounts that already had linked payment methods, so that attackers could run ads and pay for them using the account owner’s payment method.
The cloaking service would decide whether to send a user to the malicious page or an innocuous one based on the geolocated IP address of the user clicking on the ad, the presence of the correct HTTP Referer header, and other features.
The authors discovered that the confidence checks performed by the account-blocking web UI were incomplete in the server-side code, which was subsequently exploited by SilentFade. This bug allowed SilentFade to block both the Login Alerts and Facebook Business pages and ensured that users could not unblock the pages even if they tried.
Samples in this family often contain code to detect virtual machines and halt execution when detected, to thwart automated and manual analysis attempts.
This is achieved by checking the description field of all available display drivers against ‘Virtual’ or ‘VM’.
Cookies are more valuable than passwords because they contain session tokens, which are post-authentication tokens... Session tokens, on the other hand, are only issued after a successful login so the attackers can use them to bypass multi-factor authentication enabled by the user.
The data was then sent back as an encrypted JSON blob through custom HTTP headers...
42 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Facebook-focused infostealer/ad-fraud malware that leverages Meta GraphAPI to collect private Facebook account information; reported as distributed via modified pirated software and potentially unwanted programs.
A Chinese-sourced malware family cited as similar in class, targeting, and delivery methods to CopperStealer and known for compromising Facebook accounts to run deceptive ads.
SilentFade is a Windows malware family used to steal Facebook credentials and session cookies, query Facebook account metadata via the Graph API, disable account notifications, exploit a server-side page-blocking bug for persistence, and run fraudulent ads using compromised accounts and linked payment methods.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.