Researchers reported that the SYS01 information stealer has been active since at least 2022, targeting Facebook business and advertising accounts through social-engineering lures delivered by fake Facebook profiles, Google ads, and ZIP archives masquerading as games, adult videos, movies, and cracked software. The malware is also tracked as Album Stealer or S1deload Stealer, and campaigns have used compromised Facebook pages to distribute malicious archives that lure victims into launching the infection chain.
SYS01 typically abuses DLL sideloading with legitimate signed applications, then deploys an Inno Setup installer and PHP-based payloads, with newer variants adding Rust and Python components and heavier obfuscation. Researchers said it steals browser credentials, cookies, Facebook session tokens, and business-account data, while also maintaining backdoor capabilities to download and run additional payloads, upload files, execute commands, and update itself from command-and-control infrastructure. The findings underscore how stealer malware continues to enable account takeover, fraud, and broader follow-on compromise.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
Morphisec began tracking SYS01 stealer in November 2022. Its analysis linked the malware to Facebook-focused credential and session theft and multiple delivery chains including DLL sideloading.
Morphisec said the SYS01 stealer campaign was first seen in May 2022. The campaign targeted Facebook business accounts using social-engineering lures and malicious ZIP downloads.
Securelist reported that Sys01 had existed since at least 2022 and had evolved from a C# stealer to a PHP stealer. The analyzed campaign used malicious ZIP archives promoted via compromised Facebook pages and DLL sideloading to deploy payloads.
Securelist reported that Acrid, a new 32-bit C++ stealer using the Heaven’s Gate technique, was found in December. The malware steals browser data, cryptocurrency wallets, selected files, and application credentials before exfiltrating them to its C2 server.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 35 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.