Cyber Security News

Facebook Phishing Attack Chain Infrastructure Uncovered

Phishing campaigns are still the most effective way to hack a person, spread malware, infiltrate an organization or conduct any cybercriminal activities.

Though several security measures have been taken against phishing campaigns, threat actors are still coming up with various sophisticated methods for succeeding in them.

Recent reports from Zero Day’s Security Platform indicate that threat actors are currently conducting a phishing scam in the name of the social media giant “Meta” which stated a community guidelines violation on Facebook that can lead to the deactivation of the account.

One of the emails was received by PhishZDL, Zero Day Security Platform.

Phishing Email Analysis

In the same way as any other phishing campaign, this email also tends to create an emotional response from the victim that could potentially lead to clicking the embedded link in the body of the email, which will land on a phishing page.

Meta Phishing Campaign

The Phishing page had the domain hxxps://meta-business-care-7faed[.]web[.]app looks like a legitimate Meta Support team page along with the logo. The page displays the information as the page has been flagged for suspicious activity. 

Meta Phishing Page

In addition to the above message, the page has an option for victims to appeal against the suspension which asks for Email ID, Phone Number, and other details.

Submitting these details will result in the attacker getting Personally Identifiable Information (PII) that can lead to account takeovers and much more.

SSL Certified Phishing Pages

These phishing pages have an SSL certificate that was issued by Google Trust Service LLC and have multiple falsely branded phishing pages like Dropbox, Microsoft Outlook, and Sharepoint.

A complete technical analysis of these phishing campaigns has been released by Zero Day.

SSL Certified Phishing Page

The number of people that fell victim to these phishing campaigns is reported to be 40,000 or higher.

It is recommended that every individual be aware of phishing campaigns and be vigilant to protect personal information.

Eswar

Eswar is a Cyber security reporter with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is reporting data breach, Privacy and APT Threats.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago