A professionally developed malware campaign dubbed Stresspaint infected about 40,000 computers across roughly two dozen countries within days and was used to steal Facebook credentials and browser session data at scale. The malware was built for stealth, running for less than a minute while extracting saved passwords and browser cookies from copied LoginData and cookie files rather than directly accessing live browser stores, a technique intended to reduce antivirus detection.
The theft of both passwords and session cookies raised the risk that attackers could access accounts even where multifactor authentication was enabled, because valid cookies can help bypass fresh login challenges. Facebook said it was investigating the compromises and taking steps to protect and notify affected users, while the ultimate purpose of the stolen data remained unclear, with possible uses including criminal resale, identity theft, espionage, and fraudulent purchases.

Pull IOCs and campaign context straight into your stack.
7 events from the most recent confirmed update back to the earliest known activity.
Researchers analyzed an information-stealing Trojan distributed as a fake PDF reader/editor that stole Facebook session cookies, accessed Ads Manager data via the Graph API, and exfiltrated advertising and payment information. The malware also stole Amazon session cookies, and analysts said it resembled Stresspaint behaviorally but was likely a newer or inspired variant rather than a direct evolution.
Sophos published research on the Adkoob information-stealing malware, which targeted Facebook users and sought to steal ad purchase information. The campaign is a distinct precursor to the later Stresspaint-related activity in the existing timeline.
Researchers identified the Stresspaint information-stealing trojan hidden in a trojanized Windows application called 'Relieve Stress Paint,' distributed via a deceptive domain impersonating aol.net. The malware stole Chrome credentials and session cookies, and Radware said the malicious app was first observed at the start of the month before mass distribution began over the weekend.
Radware published a blog post describing the Stresspaint malware campaign targeting Facebook credentials. The post documented the credential theft technique and the scale of infections referenced in later reporting.
Facebook said it was investigating the malware findings and taking steps to protect and notify impacted users. The company also said it was not yet clear how accounts protected by multifactor authentication were affected.
After the initial count, more than 6,000 additional infections were observed, bringing the total to roughly 40,000 compromised computers within days. The activity was described as a professionally developed campaign that compromised tens of thousands of accounts.
Radware reported that the credential-stealing malware had infected nearly 34,000 computers across about two dozen countries more than five days before the Ars Technica report. The campaign was designed to steal browser cookies and saved passwords, enabling compromise of Facebook accounts.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
6 references tracked. Mallory keeps watching after this page renders.
blog.radware.com
Open sourcebleepingcomputer.com
Open sourcearstechnica.com
Open sourcebleepingcomputer.com
Open sourcesecurity.radware.com
Open sourcenews.sophos.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.