Meta Malvertising Campaign Spreads Android Crypto-Stealing Malware

A sophisticated malvertising campaign targeting Meta’s ad network has expanded from Windows to Android users worldwide, deploying an advanced version of the Brokewell malware disguised as TradingView’s premium app[1].

Since July 22, 2025, cybercriminals have launched over 75 malicious Facebook ads, reaching tens of thousands of users across the European Union[1:1]. The campaign tricks victims into downloading a malicious APK from fake domains that mimic TradingView’s official website.

The malware, an enhanced strain of Brokewell, functions as both spyware and a remote access trojan (RAT) with capabilities including:

  • Cryptocurrency theft (BTC, ETH, USDT)
  • SMS interception for banking and 2FA codes
  • Google Authenticator data extraction
  • Screen recording and keylogging
  • Camera and microphone activation
  • Remote command execution via Tor and WebSockets[1:2]

The attackers have localized their ads in multiple languages including Vietnamese, Portuguese, Spanish, Turkish, Thai, Arabic and Chinese to maximize reach[1:3]. While the Android campaign currently focuses on impersonating TradingView, the Windows version has mimicked numerous brands including Binance, Bitget, Metatrader, and OKX[1:4].


  1. Bitdefender - Malvertising Campaign on Meta Expands to Android, Pushing Advanced Crypto-Stealing Malware to Users Worldwide ↩︎ ↩︎ ↩︎ ↩︎ ↩︎

And they wonder why people block ads.

@Zerush@lemmy.ml
creator
link
fedilink
2
edit-2
13d

Minimum, better using Portmaster and block anything from Fakebook in both directions, but than also you can’t access, avoiding to click accidentaly on a link, irrelevant of which from it’s apps or services

This cause

Can’t I still use it to talk to my mom on messenger with video calls if I do that ?

@Zerush@lemmy.ml
creator
link
fedilink
1
edit-2
13d

No, at least if you don’t desactivate the filter before. Better to convince your mother to use another app.

Gee, if only there was an alternative to Meta’s stinky apps…some kind of decentralized, federated network of servers and users that’s funded by the community instead of ads and user data sales…

Ah, well. We can only dream. /s

@Zerush@lemmy.ml
creator
link
fedilink
4
edit-2
13d

Yes, would be nice, the problem is the family and friends which are using Fakebook, Whatscrap and other and you in their contact list, than you are also in the Zuckerbot To Do list, irrelevant if you’ve an account or not. Than you can’t do other as block completly Facebook from your internet as I do.

sunzu2
link
fedilink
414d

Remote command execution via Tor and WebSockets

WTF is dis

Tor is basically a way to connect to the internet anonymously.

WebSockets is basically a way for P2P connections between servers and clients.

sunzu2
link
fedilink
213d

I got that but how does this exploit work?

Threat actor using tor to exploit open websockets?

That’s just the remote control part.

promises of a free TradingView Premium app for Android. Instead of delivering legitimate software, the ads drop a highly advanced crypto-stealing trojan — an evolved version of the Brokewell malware.

From another source, that works in part by exploiting “accessibility service permissions”:

Like other recent Android malware families of its kind, Brokewell is capable of getting around restrictions imposed by Google that prevent sideloaded apps from requesting accessibility service permissions.

This includes displaying overlay screens on top of targeted apps to pilfer user credentials. It can also steal cookies by launching a WebView and loading the legitimate website, after which the session cookies are intercepted and transmitted to an actor-controlled server.

sunzu2
link
fedilink
113d

WTF, this is sounds like what graphenseOS was design to avoid…

It would maybe be safer on a custom OS because less malware would target it, but exploits can still exist, at this point I’d say you also should really be using a dedicated device for crypto wallet stuff if you have more than small amounts, whether that’s a purpose built hardware wallet, an old phone you reset and have only the wallet app on, etc.

Create a post

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

much thanks to @gary_host_laptop for the logo design :)

  • 0 users online
  • 124 users / day
  • 1.05K users / week
  • 1.3K users / month
  • 4.58K users / 6 months
  • 1 subscriber
  • 4.18K Posts
  • 106K Comments
  • Modlog