Cybersecurity researchers have uncovered a new wave of attacks targeting cryptocurrency users through Facebook. Hackers are purchasing ad slots on the platform to display convincing 'Free Upgrade to Windows 11' advertisements, complete with Microsoft's official branding, logo, and copy style — making them difficult to distinguish from legitimate promotions.
From Ad to Malware: Fake Microsoft Site
Clicking the ad redirects users to a meticulously cloned Microsoft website. The interface, layout, and even the URL are crafted to mimic the real thing, lowering users' guard. The site prompts visitors to download a 'Windows 11 update installer,' which is actually a payload for the 'Lunar Application' malware framework.
Lunar Application: Seed Phrase Theft
Once executed, Lunar Application scans the victim's computer for stored seed phrases (mnemonic backups). Gaining access to these phrases allows hackers to fully control the associated cryptocurrency wallets. The malware also harvests exchange login credentials saved in browsers, wallet app authentication data, as well as cookies and autofill information for broader account takeover.
Geofencing to Bypass Security Scanners
The attackers employ geofencing technology to filter out connection requests from data center IP addresses. This prevents automated security scanners and sandbox environments from accessing the malicious site, drastically reducing the chances of early detection and blacklisting. The technique indicates a sophisticated threat actor skilled in both social engineering and evasion tactics.
Protection Tips
To defend against such targeted attacks, crypto users should: always download updates directly from microsoft.com; never store seed phrases digitally on any computer; use hardware wallets (e.g., Ledger, Trezor) for large holdings; and regularly audit browser extensions, removing any from untrusted sources.

