Faceliker malware family
Faceliker is a malware family tracked by MalwareAnalyzer by Cyble across 3 publicly analyzed samples. First seen 2026-08-05, most recently 2026-08-11. Observed ATT&CK techniques include T1112.
Corpus statistics
- Publicly analyzed samples: 3
- First seen: 2026-08-05
- Last seen: 2026-08-11
- Verdicts: malicious 3
- File types: html 3
ATT&CK techniques used by Faceliker
- T1112 - 2 samples
Extracted command-and-control infrastructure
- http://creativecommons.org/licenses/by/3.0/ - 3 samples
- https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css - 3 samples
- http://www.bloggertipandtrick.net/ - 2 samples
- http://www.premiumbloggertemplates.com/ - 2 samples
- http://1.bp.blogspot.com/-SVWRw06Y6UE/URLY5tAnjYI/AAAAAAAACFo/5FDTDhy13CA/s1600/page_bg.jpg - 1 sample
- http://1.bp.blogspot.com/-gZeAq088yso/URLQIekivZI/AAAAAAAACEw/ddkS4dh4ueI/s1600/arrow.png - 1 sample
- http://1.bp.blogspot.com/-qJET1HGpUDc/URJ3PJ91EtI/AAAAAAAAB9k/6-zUQ4CKbmg/s1600/slider-holder.png);padding:10px;margin-left:10px;position:relative;overflow:hidden;width:920px;height:340px - 1 sample
- http://1.bp.blogspot.com/-xSH7qE6gjrY/UYH3JwRJszI/AAAAAAAAH_k/5YbjPtC_3gE/s640/ffm-firj-tania-photoshoot+%2812%29.jpg - 1 sample
- http://1.bp.blogspot.com/-xSH7qE6gjrY/UYH3JwRJszI/AAAAAAAAH_k/5YbjPtC_3gE/w1200-h630-p-k-no-nu/ffm-firj-tania-photoshoot+%2812%29.jpg - 1 sample
- http://2.bp.blogspot.com/-6p_AqXL70hQ/UQWPHMObw9I/AAAAAAAABZ0/f2UWIvjFkSQ/s1600/footerli.png - 1 sample
- http://2.bp.blogspot.com/-dgVu9b__hgI/URLbeXpM6EI/AAAAAAAACFw/3vGr4n3yVK8/s1600/sidebar+h2.jpg - 1 sample
- http://3.bp.blogspot.com/-AIW512aa4Ms/URJ2uXZh45I/AAAAAAAAB9c/QMul0JdxpNs/s1600/outerpic.png - 1 sample
- http://3.bp.blogspot.com/-IeHXc7J7dZs/URLRwVeKocI/AAAAAAAACFA/OepYPORtIII/s1600/menuh.png - 1 sample
- http://3.bp.blogspot.com/-eEgZtLbyI5A/URLe2rdcXjI/AAAAAAAACGA/Bzcm_LnSpk4/s1600/slider_item.png - 1 sample
- http://4.bp.blogspot.com/-MXCdgmCfwRc/UQezaV_MLdI/AAAAAAAABck/N-dsAOjgvtk/s1600/avatar.jpg - 1 sample
- http://4.bp.blogspot.com/-SMVDkVsdj0I/URLTaa0lVII/AAAAAAAACFQ/STj40Z_py0Q/s1600/overlay_feature.png)repeat-x - 1 sample
- http://4.bp.blogspot.com/-UzQSVqe350A/URJhGaHsGqI/AAAAAAAAB7s/UVJaEnVxtc8/s1600/body.gif);color:#aaa;font:x-small - 1 sample
- http://4.bp.blogspot.com/-WwOfybPl9ig/UQezafv_uNI/AAAAAAAABcg/uLkQHEqKKBM/s1600/arrow-right.png - 1 sample
- http://4.bp.blogspot.com/-b9OEmVdL6Q4/URA_BL7OXWI/AAAAAAAAB2k/c9exOQaNu2U/s1600/slider_item_active.png - 1 sample
- http://4.bp.blogspot.com/-bp2HK6MdDXg/T5aB6vI5GPI/AAAAAAAAF98/gwCsmb8Fcks/s1600/transparant.png);padding:10px;margin:10px - 1 sample
Recent Faceliker samples
- e299a58762177f7f92c548d0cc3f5ba324c5b078af4cd8943e4c8f58b99de6e0 - malicious (2026-08-11)
- 8f13716b4837aa49c88e08cacec55a992a69853d5ab7189a865a1b9f06e6bc7c - malicious (2026-08-07)
- 885f94016a2a5b47713779100c8d4e8f180bc8e7208794da180942eccb798ca9 - malicious (2026-08-05)
Frequently asked about Faceliker
- What is Faceliker?
- Faceliker is a malware family tracked by MalwareAnalyzer by Cyble across 3 publicly analyzed samples. First seen 2026-08-05, most recently 2026-08-11. Observed ATT&CK techniques include T1112.
- How many Faceliker samples have been analyzed?
- MalwareAnalyzer by Cyble holds 3 publicly analyzed samples attributed to Faceliker, first seen 2026-08-05 and most recently 2026-08-11. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does Faceliker use?
- Across our Faceliker samples the most frequently observed techniques are T1112 (2). Counts are the number of analyzed samples in which each technique was observed.
- What file types does Faceliker use?
- Faceliker samples in this corpus are distributed as html (3).
- Does Faceliker use command-and-control infrastructure?
- Yes. 37 distinct command-and-control indicators have been extracted from Faceliker samples, either from static configuration or from traffic captured during sandbox detonation. The full list is published on the family page.
- Is Faceliker malicious?
- 3 of 3 analyzed Faceliker samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends