Join us at Black Hat and discover how we’re reshaping the cybersecurity landscape. Learn More

In part one of the SYS01 Malvertising campaign research, LevelBlue SpiderLabs looked at how threat actors have been utilizing Facebook advertising to propagate information stealing and account takeover malware.

In part two of the research, the team analyzes some of the changes that have been implemented into the malware, and some similarities to another campaign that LevelBlue has previously uncovered. As the threat actors behind the SYS01 campaign have continued to modify their malware to meet new objectives, we expect further development and changes.

Related Resources

Current: resourcesresearch-reportsfacebook-malvertising-epidemic-unraveling-a-persistent-threat-sys01-part-2
Resource: resourcesresearch-reportsttp-briefing-q2-2026
Research Report

Q2 TTP Briefing: Latest Threats & Trends from the Frontlines

Current: resourcesresearch-reportsfacebook-malvertising-epidemic-unraveling-a-persistent-threat-sys01-part-2
Resource: resourcesresearch-reportsquimarat-a-java-rat-with-burning-ambitions
Research Report

QuimaRAT: A Java RAT with Burning Ambitions

Current: resourcesresearch-reportsfacebook-malvertising-epidemic-unraveling-a-persistent-threat-sys01-part-2
Resource: resourcesresearch-reportsttp-briefing-q1-2026
Research Report

Q1 2026 TTP Briefing: Latest Threats & Trends from the Frontlines