Fabookie is a Windows credential-stealing malware family focused on hijacking Facebook-related access, particularly Facebook Ads accounts, by stealing browser session cookies and authentication material. It has been described as a modular credential theft component with multiple modules for collecting authentication data for various services and websites, and is commonly categorized among information stealers.
Fabookie has been observed in malware distribution ecosystems operated on a pay-per-install basis, including campaigns using PrivateLoader and TaskLoader, and has also appeared in broader cracked-software and fake-installer delivery chains associated with malware droppers such as NullMixer. In these operations, victims are typically lured through pirated-software or fake software download themes and then infected with downstream payloads selected by the loader operator.
Operationally, Fabookie is associated with theft of browser session cookies rather than only static credentials, enabling attackers to abuse authenticated web sessions and monetize compromised Facebook advertising accounts. Reporting also notes use against Facebook Ads specifically. In at least one observed campaign, the Fabookie payload was concealed within an image as part of the delivery chain. The malware is primarily relevant to financially motivated cybercrime activity targeting users and organizations that manage online advertising assets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
Keylogger. Enables the malware to intercept the codes of keys pressed by the user on the keyboard.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Stealer targeting Facebook advertising accounts and browser session cookies, with account and payment data harvesting via Facebook Graph API queries.
Information stealer observed as a payload delivered by PrivateLoader.
Information-stealing malware focused on hijacking Facebook Ads accounts by stealing session cookies and querying Facebook Graph APIs to collect account/payment details; observed downloading an image that contains an embedded PE payload.
A malware family observed among payloads distributed by PrivateLoader, including in manually analyzed unknown samples.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.