Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

SYS01 Stealer is an information-stealing malware family that has been reported in campaigns targeting employees connected to critical government infrastructure, as well as people in manufacturing and other industries. It uses deceptive ads and download pages to deliver malware that can steal browser data and Facebook business-account information, then send data to command-and-control (C2) servers. Reports describe activity tracked from November 2022 and a broader malvertising campaign documented by Malaysia’s MyCERT in 2024.

What is SYS01 Stealer?

SYS01 is an infostealer: malware designed to collect sensitive information from an infected computer and transmit it to an attacker. Reporting based on Morphisec research describes it as both a credential- and session-stealing threat and a tool capable of additional remote actions, including downloading or executing files and uploading local files.

The government connection needs careful qualification. Morphisec-linked reporting says the activity included employees connected to critical government infrastructure; it also identified manufacturing and other industries. That does not establish that every campaign targets government workers, that a particular government agency was compromised, or that the malware is exclusively used for espionage.

When was SYS01 reported, and what does the timeline establish?

  • November 2022: Morphisec’s 2023 reporting said its tracking of SYS01 activity began then.
  • March 2023: Public reporting described the malware and its targeting, based on Morphisec research.
  • September 2024: MyCERT recorded the first detection timing for a later malvertising campaign, which its advisory described as global and involving impersonation of trusted brands and software.

These dates document reported activity and detections, not the malware’s precise origin or the start of every SYS01 campaign. The cited reporting does not establish a reliable victim count, prevalence rate, or financial-loss total.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
CZUR ET MAX Professional Book & Document Scanner, 38MP Document Camera
  • High-Resolution Scanning: Features a 38MP CMOS sensor with a resolution of 7168 × 5376 and 410 DPI, suitable for capturing clear and detailed images
  • Patented Curve-Flattening Technology: Automatically flattens the curved pages of bound books and removes distortion for accurate, clean scans without the need to unbind
  • Powerful OCR Functionality: Converts scanned images into editable and searchable files, including Word, Excel, and searchable PDFs. Supports 180+ languages. Please note that Thai and Hebrew are currently not supported. Arabic is only supported on ET Series scanners under Windows systems; other operating systems currently do not support Arabic OCR. If you need the complete OCR language support list, please feel free to contact us for more details
  • Large Scanning Area: Supports documents up to A3 size (16.5'' × 11.7''). Note: Not recommended for glossy or highly reflective materials
  • Fast Scanning Speed: Scan a page in just 1.5 seconds with practiced operation—ideal for high-efficiency, bulk scanning projects

How does SYS01 reach a victim?

Reported lures vary, but the common pattern is to make a malicious download look like something the user wants. Campaigns have used Google Ads, social-media malvertising, and fake Facebook profiles to direct people to ZIP archives presented as games, movies, adult content, software, or AI tools.

A person who follows the ad or profile and opens the archive may see what appears to be a legitimate program. The archive can contain a legitimate executable that is vulnerable to DLL side-loading, together with a malicious DLL. Side-loading occurs when the executable loads the attacker’s library instead of, or alongside, the expected library. The executable’s legitimacy does not make the downloaded package safe.

Rank #2
WoneNice USB Laser Barcode Scanner Wired Handheld Bar Code Scanner Reader Black
  • Plug and play, This laser handheld barcode scanner has simple installation with any USB port and Ideal for businesses, shops and warehouse operations. Its function is unbeatable and easy to use, design is stylish
  • Compatible with Windows, Mac, and Linux; works with Word, Excel, Novell, and all common software
  • Scanning Speed: 200 scans per second. Scanning angle: Inclination angle 55°, Elevation angle 65°. Operational Light Source:Visible Laser 650-670nm.
  • Decode Capability: Code11, Code39, Code93, Code32, Code128, Coda Bar, UPC-A, UPC-E, EAN-8, EAN-13, ISBN/ISSN, JAN.EAN/UPC Add-on2/5 MSI/Plessey, Telepen and China Postal Code,Interleaved 2 of 5, Industrial 2 of 5, Matrix 2 of 5, etc ; 300 configurable options for prefix, suffix and termination strings, support turn on/off the beep.
  • Color: Black. Dimensions: 3.6 x 2.6 x 6.1 inches. Type of Cable: 2M or 6ft straight cable. Shock: 1.5m drop on concrete surface. Regulatory Approvals: FCC CE.

What happens after SYS01 runs?

  1. The downloaded archive is opened. It contains the loader and malicious library used in the reported infection chain.
  2. The library is loaded by the executable. The malicious DLL uses the side-loading opportunity to start the next stage.
  3. An installer deploys additional components. Reporting based on Morphisec research describes an Inno Setup installer deploying a PHP application.
  4. A scheduled task can maintain persistence. The task is used to help the malware run again after the initial execution.
  5. The malware collects information and communicates with C2 infrastructure. The PHP components can check Facebook login state, collect data, download or execute files, upload local files, and transmit information to attacker-controlled servers.

MyCERT’s 2024 advisory also notes covert execution, obfuscation, and memory-resident or fileless behavior in some campaigns. Those techniques can make activity less visible to users and complicate detection; they do not mean that every infection uses the same execution method.

What information can SYS01 steal?

The reported targets span both browser data and account information. MyCERT’s 2024 advisory lists browser credentials, cookies, session tokens, payment details, system information, and autocomplete data. Morphisec-linked reporting also describes theft of Facebook business-account information.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
Epson Workforce ES-50 Compact & Lightweight Mobile Document Scanner
  • PORTABLE SCANNER FOR USE ON-THE-GO — The fastest and lightest mobile single-sheet-fed compact document scanner in its class¹
  • QUICK DOCUMENT SCANNING ― This Epson ultra-fast scanner scans a single page as quickly as 5.5 seconds²; Windows and Mac compatible
  • VERSATILE PAPER HANDLING ― Portable scanner scans documents up to 8.5 x 72 in; Also easily digitizes receipts and ID cards to make accounting, bookkeeping, and organizing simpler
  • INTUITIVE, HIGH-SPEED SOFTWARE — Epson ScanSmart Software³ is a smart tool allowing you to easily scan, review, and save; Stay organized easily with the help of this Epson scanner
  • EASY SETUP — USB-powered connect to your computer for quick and simple scanning; No batteries or external power supply required to operate portable document scanner; Standard Connectivity: USB 2.0
  • Browser credentials: Saved usernames and passwords can expose accounts if the data is obtained and usable.
  • Cookies and session tokens: These can represent an already-authenticated browser session. A stolen session may create account risk even when the password itself is not the only item taken.
  • Payment and autocomplete data: Information stored for convenience in a browser may include sensitive details users have entered before.
  • Facebook business-account information: Access to a business account can put associated pages or business activity at risk. The reporting describes this as a collection target, not proof that a particular account was taken over.
  • System information and files: The malware can collect information about the system and, according to the reporting, can upload local files or retrieve and execute files through C2 instructions.

Why does Facebook business-account theft matter?

For an employee or organization that manages a Facebook business presence, browser-session theft can create a different risk from a simple password leak. If an attacker can use a valid session or account data, they may be able to access business resources under the victim’s account. SYS01 reporting specifically combines that business-account focus with browser credential and session-data collection.

The reports do not quantify how often attackers successfully take over a business account, nor do they establish that every infected device has a Facebook session available to steal. Treat the account exposure as a risk to investigate, not as an automatic consequence of infection.

Rank #4
Sale
Canon imageFORMULA R10 - Portable Document Scanner, USB Powered, Duplex Scanning, Document Feeder, Easy Setup, Convenient, Perfect for Mobile Users, White
  • STAY ORGANIZED – Easily convert your paper documents into digital formats like searchable PDF files, JPEGs, and more.Power Consumption : 2.5W or less (Energy Saving Mode: 0.7W). Suggested Daily Volume : 500 scans..Does it contain liquid: no
  • CONVENIENT AND PORTABLE –lightweight and small in size, you can take the scanner anywhere from home offices, classrooms, remote offices, and anywhere in between
  • HANDLES VARIOUS MEDIA TYPES – Digitize receipts, business cards, plastic or embossed cards, reports, legal documents, and more
  • FAST AND EFFICIENT – No technical hurdles or complicated setups here; easily scan both sides of a document at the same time, in color or black-and-white, at up to 12 pages-per-minute, and with a 20 sheet automatic feeder
  • BROAD COMPATIBILITY – Works with both Windows and Mac devices, be it laptop or computer
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How can an organization reduce the risk?

Morphisec’s prevention guidance, reproduced in SecurityWeek’s report, emphasizes zero-trust policies, limiting users’ rights to download and install programs, and training users to recognize social-engineering tactics. Those controls address both the deceptive entry point and the execution chain.

Reduce risky downloads and execution

  • Restrict users’ ability to install software, and use application-control policies to limit which programs can run.
  • Apply zero-trust principles so that a download, executable, or user account is not trusted merely because it appears legitimate or comes from an expected-looking page.
  • Give particular scrutiny to ZIP archives offered through ads, social profiles, or download pages, especially when they promise games, entertainment, software, or AI tools.

Watch for browser and endpoint abuse

  • Monitor endpoints for unexpected executable and DLL behavior, installer activity, and scheduled tasks associated with software a user did not intentionally install.
  • Review browser and account activity for suspicious access or changes, particularly where a device may have contained saved credentials or an authenticated Facebook business session.
  • Use endpoint and browser protections appropriate to the organization, while recognizing that the reported obfuscation and memory-resident behavior can make a single detection control insufficient.

Train users around the lure

Explain that malicious ads and fake profiles can lead to archives disguised as legitimate downloads. Encourage staff to obtain software through approved channels and to report unexpected download prompts instead of opening the archive to see what it contains.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
FixMeStick Gold Computer Virus Removal Stick for Windows PCs - Unlimited Use on Up to 5 Laptops or Desktops for 2 Years - Works with Your Antivirus
  • WHAT YOU GET: FixMeStick Virus Removal Tool for Windows PCs (Windows XP, Vista, 7, 8, 8.1, 10, and 11. 512 MB RAM required), Getting Started Guide, our virus removal guarantee backed by our friendly Canadian based Customer Support Team.

What should you do if you suspect an infection?

Because SYS01 is reported to steal credentials and session data and to communicate with C2 servers, treat a suspected infection as both an endpoint and an account-security incident. The following are practical response steps based on those reported capabilities:

  1. Contact your security team and contain the device. Follow organizational incident procedures; avoid continuing to use the suspected computer for sensitive work.
  2. Use a known-clean device to secure accounts. Change potentially exposed passwords and revoke active sessions where the relevant service provides that option. Prioritize accounts that were signed in or had credentials saved in the affected browser.
  3. Review Facebook business access. Check recent account activity, business settings, and administrators or other access for changes you do not recognize.
  4. Have responders investigate the endpoint. They can examine the downloaded archive, executable and DLL activity, installer behavior, scheduled tasks, and signs of file transfer or C2 communication.
  5. Preserve useful evidence. Record the download source and time, keep relevant alerts and logs, and coordinate remediation with responders rather than deleting artifacts before they can be assessed.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.