An upgraded version of Python NodeStealer, a notorious infostealer, is now capable of targeting Facebook Ads Manager accounts.
It can steal credit card information, as well as credentials stored in the browser's 'Web Data' database.
The infostealer utilizes Windows Restart Manager to unlock database files and extracts the stolen information into a temporary folder.
Python NodeStealer is believed to be developed by a threat actor located in Vietnam, with the goal of compromising Facebook Business and Ads Manager accounts.