{"id":53632,"date":"2023-09-12T16:30:00","date_gmt":"2023-09-12T16:30:00","guid":{"rendered":"https:\/\/www.darkreading.com\/endpoint\/millions-facebook-business-accounts-python-malware"},"modified":"2023-09-12T16:30:00","modified_gmt":"2023-09-12T16:30:00","slug":"millions-of-facebook-business-accounts-bitten-by-python-malware","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/millions-of-facebook-business-accounts-bitten-by-python-malware\/","title":{"rendered":"Millions of Facebook Business Accounts Bitten by Python Malware"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/bltf34e8fb49828a01d\/647a4b3565658f7bbb22a892\/python-Ernie_Janes-Alamy.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>Attackers are targeting millions of <a href=\"https:\/\/www.darkreading.com\/attacks-breaches\/facebook-business-pages-chatbot-data-harvesting-campaign\" target=\"_blank\" rel=\"noopener\">Facebook business accounts<\/a> with malicious messages, sent&nbsp;via Facebook Messenger&nbsp;from a botnet of fake and <a href=\"https:\/\/www.darkreading.com\/application-security\/ducktail-spearphishing-linkedin-hijack-facebook-business-accounts\" target=\"_blank\" rel=\"noopener\">hijacked<\/a> personal Facebook accounts. The goal is to spread&nbsp;an info-stealing malware that can intercept browsing sessions and account cookies, and it&#8217;s hitting 100,000 <a href=\"https:\/\/www.darkreading.com\/attacks-breaches\/attackers-dangle-ai-based-facebook-ad-lures-to-take-over-business-accounts\" target=\"_blank\" rel=\"noopener\">Facebook business accounts<\/a> per week, according to researchers.<\/p>\n<p>The Python-based stealer&nbsp;successfully infects about 1.4% of targets \u2014 or about one out of 70 of those reached,&nbsp;<a href=\"https:\/\/labs.guard.io\/mrtonyscam-botnet-of-facebook-users-launch-high-intent-messenger-phishing-attack-on-business-3182cfb12f4d\" target=\"_blank\" rel=\"noopener\">Guardio Labs revealed in a blog post<\/a> on Sept. 11.&nbsp;Guardio has dubbed the effort the &#8220;MrTonyScam,&#8221; based on the name of the administrator of a Telegram channel with which the stealer interacts.<\/p>\n<p>&#8220;Facebook\u2019s Messenger platform has been heavily abused in the past month to spread endless messages with malicious attachments from a swarm of fake and hijacked personal accounts,&#8221; <span>Oleg Zaytsev, a <\/span>Guardio Labs security researcher, wrote in the post.<\/p>\n<p>Indeed, there has been an uptick recently in various threat campaigns aimed at <a href=\"https:\/\/www.darkreading.com\/application-security\/chatgpt-browser-extension-hijacks-facebook-business-accounts\" target=\"_blank\" rel=\"noopener\">hijacking Facebook business accounts<\/a>, all of which is&nbsp;supporting a thriving business on Telegram dark markets to sell these accounts to cybercriminals to use for further nefarious activity.<\/p>\n<p>&#8220;We see numerous channels and users offering everything from specific high-value accounts to &#8216;logs&#8217; of hundreds and thousands of hijacked business accounts (BM \u2014 Business Manager), advertisement accounts with reputation, or even linked payment methods and credits (Agency Accounts),&#8221; Zaytsev wrote.<\/p>\n<h2 class=\"regular-text\">MrTonyScam Facebook Attack&nbsp;Details<\/h2>\n<p>Some of the tactics and techniques of the campaign match previous ones used by a Vietnam-based threat actor, according to the research \u2014 with the bulk of the victims of the far-reaching campaign being based in North America, Europe, Asia, and Australia.<\/p>\n<p>From a technical standpoint, the attack&#8217;s messages contain a compressed stealer payload that targets the victims\u2019 installed browsers to lift&nbsp;session cookies; these are then sent to threat actors&#8217; IM channels in a &#8220;swift and effective operation,&#8221; Zaytsev wrote.<\/p>\n<p>He added that there are several aspects to the campaign that appear to contribute to its unusual rate of success \u2014 despite requiring action on the part of message recipients. One is the ability for messages \u2014 which vary in content but share similar context \u2014 to slip past spam detectors that scan for mass mailings. For instance, some of the messages are complaints addressing the page for violating policies, while others may include questions related to a product that is likely advertised by the target account. This variation and the use of different filenames, as well as the addition of Unicode characters to different words, &#8220;make each message unique,&#8221; Zaytsev wrote.<\/p>\n<p>The messages also contain a link that appears to be relevant to the content sent in the message, such as a link to product to check its availability. If clicked, the link downloads a &#8220;<a href=\"https:\/\/www.darkreading.com\/endpoint\/mysterious-mystic-stealer-spreads-wildfire-mere-months\" target=\"_blank\" rel=\"noopener\">classic stealer<\/a>&#8221; payload archived with RAR or zip formats, which then uses a multistep process and five layers of obfuscation to hide its content, Zaytsev wrote. The payload also is generated on the fly to avoid static detection.<\/p>\n<p>&#8220;The attack flow is a combination of techniques, free\/open platform abuse, as well as numerous obfuscation and hiding methods \u2014 summing to a quite complex flow,&#8221; according to the researcher.<\/p>\n<p>Once executed, the&nbsp;&#8220;simple, straightforward Python script extracts all cookies and login data (saved usernames and passwords) from several popular browsers it looks for on the victim&#8217;s computer,&#8221; he explained in the post. &#8220;All this together is sent to a Telegram channel using Telegram&#8217;s\/Discord bot API, which is a common practice among scammers.&#8221;<\/p>\n<p>The payload&#8217;s final act is to delete all cookies after stealing them, effectively locking victims out of their accounts. This gives the scammers time to hijack their session and replace the password so victims can&#8217;t revoke the stolen session or change the password themselves, Zaytsev said.<\/p>\n<h2 class=\"regular-text\">Exposing Security Holes<\/h2>\n<p>MrTonyScam and other campaigns targeting <a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/meta-300k-bounty-mobile-rce-vulnerabilities-facebook\" target=\"_blank\" rel=\"noopener\">Facebook<\/a> business users demonstrate how threat actors continue to expose security loopholes in both modern browsers \u2014 which continue to store easily decrypted passwords and user cookies \u2014 as well as social media services like Facebook, he said.<\/p>\n<p>&#8220;Threat actors will always find new ways to get to us, hijack social accounts, and abuse legitimate services for their malicious deeds,&#8221; Zaytsev wrote. Meanwhile, Facebook and other social media services still fail to detect account hijacking in real time, while the <a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/breachforums-shuts-down-leaders-arrest\" target=\"_blank\" rel=\"noopener\">Dark Web cybercriminal ecosystem<\/a> thrives and <a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/interpol-shuts-down-phishing-service-16shops\" target=\"_blank\" rel=\"noopener\">attracts<\/a> more and more threat actors, he wrote.<\/p>\n<p>These threats demand even more vigilance on the part of users to consider with suspicion any and all messages from users they don&#8217;t recognize, as well as the use of &#8220;more layers of security detection&#8221; to counter malicious messages before they reach a social-media inbox, Zaytsev advised.<\/p>\n<p>Read More <a href=\"https:\/\/www.darkreading.com\/endpoint\/millions-facebook-business-accounts-python-malware\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The &#8220;MrTonyScam&#8221; has a surprisingly high success rate, spreading a Python-based stealer to some 100,000 business accounts per week.Read More <a href=\"https:\/\/www.darkreading.com\/endpoint\/millions-facebook-business-accounts-python-malware\">HERE<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[151],"tags":[],"class_list":["post-53632","post","type-post","status-publish","format-standard","hentry","category-darkreading-ti"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Millions of Facebook Business Accounts Bitten by Python Malware 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/millions-of-facebook-business-accounts-bitten-by-python-malware\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Millions of Facebook Business Accounts Bitten by Python Malware 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/millions-of-facebook-business-accounts-bitten-by-python-malware\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2023-09-12T16:30:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/bltf34e8fb49828a01d\/647a4b3565658f7bbb22a892\/python-Ernie_Janes-Alamy.jpg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/millions-of-facebook-business-accounts-bitten-by-python-malware\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/millions-of-facebook-business-accounts-bitten-by-python-malware\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Millions of Facebook Business Accounts Bitten by Python Malware\",\"datePublished\":\"2023-09-12T16:30:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/millions-of-facebook-business-accounts-bitten-by-python-malware\\\/\"},\"wordCount\":791,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/millions-of-facebook-business-accounts-bitten-by-python-malware\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/bltf34e8fb49828a01d\\\/647a4b3565658f7bbb22a892\\\/python-Ernie_Janes-Alamy.jpg\",\"articleSection\":[\"DarkReading |TI\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/millions-of-facebook-business-accounts-bitten-by-python-malware\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/millions-of-facebook-business-accounts-bitten-by-python-malware\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/millions-of-facebook-business-accounts-bitten-by-python-malware\\\/\",\"name\":\"Millions of Facebook Business Accounts Bitten by Python Malware 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/millions-of-facebook-business-accounts-bitten-by-python-malware\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/millions-of-facebook-business-accounts-bitten-by-python-malware\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/bltf34e8fb49828a01d\\\/647a4b3565658f7bbb22a892\\\/python-Ernie_Janes-Alamy.jpg\",\"datePublished\":\"2023-09-12T16:30:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/millions-of-facebook-business-accounts-bitten-by-python-malware\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/millions-of-facebook-business-accounts-bitten-by-python-malware\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/millions-of-facebook-business-accounts-bitten-by-python-malware\\\/#primaryimage\",\"url\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/bltf34e8fb49828a01d\\\/647a4b3565658f7bbb22a892\\\/python-Ernie_Janes-Alamy.jpg\",\"contentUrl\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/bltf34e8fb49828a01d\\\/647a4b3565658f7bbb22a892\\\/python-Ernie_Janes-Alamy.jpg\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/millions-of-facebook-business-accounts-bitten-by-python-malware\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Millions of Facebook Business Accounts Bitten by Python Malware\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Millions of Facebook Business Accounts Bitten by Python Malware 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/millions-of-facebook-business-accounts-bitten-by-python-malware\/","og_locale":"en_US","og_type":"article","og_title":"Millions of Facebook Business Accounts Bitten by Python Malware 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/millions-of-facebook-business-accounts-bitten-by-python-malware\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2023-09-12T16:30:00+00:00","og_image":[{"url":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/bltf34e8fb49828a01d\/647a4b3565658f7bbb22a892\/python-Ernie_Janes-Alamy.jpg","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/millions-of-facebook-business-accounts-bitten-by-python-malware\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/millions-of-facebook-business-accounts-bitten-by-python-malware\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Millions of Facebook Business Accounts Bitten by Python Malware","datePublished":"2023-09-12T16:30:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/millions-of-facebook-business-accounts-bitten-by-python-malware\/"},"wordCount":791,"commentCount":0,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/millions-of-facebook-business-accounts-bitten-by-python-malware\/#primaryimage"},"thumbnailUrl":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/bltf34e8fb49828a01d\/647a4b3565658f7bbb22a892\/python-Ernie_Janes-Alamy.jpg","articleSection":["DarkReading |TI"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.threatshub.org\/blog\/millions-of-facebook-business-accounts-bitten-by-python-malware\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/millions-of-facebook-business-accounts-bitten-by-python-malware\/","url":"https:\/\/www.threatshub.org\/blog\/millions-of-facebook-business-accounts-bitten-by-python-malware\/","name":"Millions of Facebook Business Accounts Bitten by Python Malware 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/millions-of-facebook-business-accounts-bitten-by-python-malware\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/millions-of-facebook-business-accounts-bitten-by-python-malware\/#primaryimage"},"thumbnailUrl":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/bltf34e8fb49828a01d\/647a4b3565658f7bbb22a892\/python-Ernie_Janes-Alamy.jpg","datePublished":"2023-09-12T16:30:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/millions-of-facebook-business-accounts-bitten-by-python-malware\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/millions-of-facebook-business-accounts-bitten-by-python-malware\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/millions-of-facebook-business-accounts-bitten-by-python-malware\/#primaryimage","url":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/bltf34e8fb49828a01d\/647a4b3565658f7bbb22a892\/python-Ernie_Janes-Alamy.jpg","contentUrl":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/bltf34e8fb49828a01d\/647a4b3565658f7bbb22a892\/python-Ernie_Janes-Alamy.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/millions-of-facebook-business-accounts-bitten-by-python-malware\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Millions of Facebook Business Accounts Bitten by Python Malware"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/53632","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=53632"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/53632\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=53632"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=53632"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=53632"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}