Facestealer is an Android malware family focused on stealing Facebook credentials and associated session data from users of trojanized mobile applications. It has been distributed through malicious apps masquerading as benign utilities such as photo editors, fitness tools, scanners, wallpapers, VPNs, and media-related applications, including apps published on Google Play and in some cases third-party app stores. The family was publicly documented in 2021 and has since appeared in numerous variants with frequent code changes and obfuscation updates.
A common Facestealer infection flow presents the victim with Facebook’s legitimate login page inside an Android WebView and injects malicious JavaScript to intercept usernames, passwords, user-agent information, and cookies. Some variants retrieve remote configuration data at runtime, enabling operators to alter behavior without repackaging the app. Collected data is then exfiltrated to attacker-controlled infrastructure, often after local encryption or with portions of the logic moved into native code to hinder analysis and detection. Beyond credential theft, the malware’s theft of session cookies can enable direct account takeover and abuse of authenticated sessions.
Facestealer has been associated with large-scale malicious app campaigns, including clusters comprising hundreds of samples. Observed apps accumulated substantial install counts before removal from official marketplaces. Stolen Facebook accounts can be leveraged for follow-on phishing, fraudulent advertising activity, fake social-media posts, and broader social-engineering operations. The malware primarily targets Android users and is best characterized as a mobile credential-stealing trojan with spyware-like data collection behavior.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
Once the Facebook’s official page loads into the WebView object, the malware injects malicious JavaScript code into that page and extracts all the necessary information like account, password, user-agent and cookie information.
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mobile spyware distributed via fake Google Play apps that steals Facebook credentials by presenting a Facebook login in a WebView, injecting JavaScript to capture entered credentials, collecting cookies after login, and exfiltrating PII and session data to a remote server.
An Android trojan that socially engineers victims into providing Facebook login credentials, which are then sent to a Russian server.
Android malware distributed via trojanized Google Play apps that tricks users into logging into Facebook through a legitimate-looking page, injects malicious JavaScript to steal credentials, sends them to a command-and-control server, and harvests account data including email addresses, IP addresses, phone numbers, conversations, messaging histories, credit-card details and friend lists.
Android malware family distributed via Google Play and third-party app stores that impersonates popular apps, opens Facebook's legitimate login page in a WebView, injects malicious JavaScript, and steals credentials, cookies, user-agent data, and related account information before exfiltrating it to a C2 server.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.