← Back to BrewedIntel
malwarehighCrypto-stealingMalvertisingMobile Malware

Aug 26, 2025 • Ionut Alexandru BALTARIU

Malvertising Campaign on Meta Expands to Android, Pushing Advanced Crypto-Stealing Malware to Users Worldwide

Bitdefender Labs has identified a significant malvertising campaign leveraging Meta's advertising infrastructure to distribute advanced crypto-stealing...

Source
Bitdefender Labs
Category
malware
Severity
high

Executive Summary

Bitdefender Labs has identified a significant malvertising campaign leveraging Meta's advertising infrastructure to distribute advanced crypto-stealing malware. Initially targeting Windows desktop users with fraudulent trading platform advertisements, the campaign has now expanded to target Android users globally. This shift indicates a strategic pivot by threat actors to exploit the perceived security of mobile devices. The malicious ads lure victims into downloading compromised applications designed to harvest cryptocurrency credentials and wallet data. The widespread nature of Meta's ad network amplifies the potential impact, putting millions of users at risk of financial loss. While specific threat actor groups and malware family names were not disclosed in the available text, the campaign underscores the critical need for vigilance. Users are advised to verify ad sources, avoid downloading unofficial apps, and employ robust mobile security solutions to mitigate the risk of credential theft and financial compromise.

Summary

Many people believe that smartphones are somehow less of a target for threat actors. They couldn’t be more wrong. Bitdefender Labs warns that cybercriminals are doubling down on spreading malware through Meta’s advertising system. After months of targeting Windows desktop users with fake ads for trading and cryptocurrency platforms, hackers are now shifting towards Android users worldwide. Bitdefender researchers recently uncovered a wave of malicious ads on Facebook that lure targets with pro

Published Analysis

Bitdefender Labs has identified a significant malvertising campaign leveraging Meta's advertising infrastructure to distribute advanced crypto-stealing malware. Initially targeting Windows desktop users with fraudulent trading platform advertisements, the campaign has now expanded to target Android users globally. This shift indicates a strategic pivot by threat actors to exploit the perceived security of mobile devices. The malicious ads lure victims into downloading compromised applications designed to harvest cryptocurrency credentials and wallet data. The widespread nature of Meta's ad network amplifies the potential impact, putting millions of users at risk of financial loss. While specific threat actor groups and malware family names were not disclosed in the available text, the campaign underscores the critical need for vigilance. Users are advised to verify ad sources, avoid downloading unofficial apps, and employ robust mobile security solutions to mitigate the risk of credential theft and financial compromise. Many people believe that smartphones are somehow less of a target for threat actors. They couldn’t be more wrong. Bitdefender Labs warns that cybercriminals are doubling down on spreading malware through Meta’s advertising system. After months of targeting Windows desktop users with fake ads for trading and cryptocurrency platforms, hackers are now shifting towards Android users worldwide. Bitdefender researchers recently uncovered a wave of malicious ads on Facebook that lure targets with pro Many people believe that smartphones are somehow less of a target for threat actors. They couldn’t be more wrong. Bitdefender Labs warns that cybercriminals are doubling down on spreading malware through Meta’s advertising system. After months of targeting Windows desktop users with fake ads for trading and cryptocurrency platforms, hackers are now shifting towards Android users worldwide. Bitdefender researchers recently uncovered a wave of malicious ads on Facebook that lure targets with pro