Facebook phishing campaign nets millions in IDs and cash
- Reference: 1654796800
- News link: https://www.theregister.co.uk/2022/06/09/facebook_phishing_campaign/
- Source link:
Identified by security researchers at phishing prevention company Pixm in late 2021, [1]the campaign has only been running since the final quarter of last year, but has already proven incredibly successful. Just one landing page - out of around 400 Pixm found - got 2.7 million visitors in 2021, and has already tricked 8.5 million viewers into visiting it in 2022.
The flow of this phishing campaign isn't unique: Like many others targeting users on social media, the attack [2]comes as a link sent via DM from a compromised account. That link performs a series of redirects, often through malvertising pages to rack up views and clicks, ultimately landing on a fake Facebook login page. That page, in turn, takes the victim to advert landing pages that generate additional revenue for the campaign's organizers.
[3]
Where this campaign differs is in how good it is at avoiding Facebook's phishing detection methods by using app deployment services like glitch.me, famous.co and amaze.co to begin a redirect chain.
[4]
[5]
"In terms of what lands in [FB user inboxes], it's a link generated using a legitimate service that Facebook could not outright block without blocking legitimate apps and links as well," Pixm said in its blog post reporting the campaign.
That's a lot of phish
The sheer scale of the campaign is remarkable. As mentioned above, Pixm identified some 400 unique phishing pages; an analysis of a random 17 of them showed an average of 985,228 page views. Extrapolate that to 400 pages and you get 399,017,673 visits. "We estimate that the 400 usernames identified so far, and all of their unique phishing pages, only represent a fraction of this campaign," Pixm said.
[6]Microsoft seizes 41 domains tied to 'Iranian phishing ring'
[7]Watch out for phishing emails that inject spyware trio
[8]Cops' Killer Bee stings credential-stealing scammer
[9]Suspected phishing email crime boss cuffed in Nigeria
The attacker, who reportedly spoke to an OWASP researcher in late 2021, said they made $150 for every thousand visits from US Facebook users. That puts the campaign's earnings at $59 million, but Pixm believes the person who spoke to OWASP was exaggerating. However, "the revenue is still likely staggering considering the size of the campaign," Pixm said.
Using app hosting services to circumvent URL blocking is a growing trend, Pixm said. "A majority of security suites which analyze domains for suspicious properties would allow a connection to these domains to proceed." Pixm noted that the domains hosting the malicious pages satisfy multiple key metrics of trustworthiness.
Pixm claims to have identified the individual behind the campaign and has handed their evidence over to INTERPOL and the police in Columbia, where the person they identified allegedly operates out of. Hopefully that means this massive campaign draws to a close soon, but don't expect it to be the last.
[10]
"As long as these domains remain undetected by use of legitimate services, these phishing tactics will continue to flourish," Pixm said. ®
Get our [11]Tech Resources
[1] https://pixmsecurity.com/blog/blog/phishing-tactics-how-a-threat-actor-stole-1m-credentials-in-4-months/
[2] https://blog.malwarebytes.com/scams/2022/06/facebook-users-targeted-in-massive-phishing-campaign/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YqJtgqwO1CxVGAmz9BQdVQAAAIA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YqJtgqwO1CxVGAmz9BQdVQAAAIA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YqJtgqwO1CxVGAmz9BQdVQAAAIA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2022/06/07/microsoft_bohrium_domains/
[7] https://www.theregister.com/2022/06/01/phishing-rat-bitrat-fortinet/
[8] https://www.theregister.com/2022/05/31/killer_bee_interpol/
[9] https://www.theregister.com/2022/05/26/nigerian_phishing_arrest/
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YqJtgqwO1CxVGAmz9BQdVQAAAIA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[11] https://whitepapers.theregister.com/
Re: The critical link
agreed, not only is FB complainant with criminals, they also likely looking the other way since they are getting paid to run the adds. Not unlike they did with Cambridge Analytica, and a never ending list of scammers that can buy adds without verification.
Funny thing is FB can push fake/scam adds all day, but comment that those adds are scam and you could get banned from the platform for a week to a month.
The mystery of Facebook
It's been well documented for several years that FB is the home of the scam. From clickbait links to fraudulent and phishing adverts. Yet we still keep hearing stories of people getting ripped off because they bought something they saw advertised on FB or giving their personal information out to someone who claims to know them. Things they wouldn't dream of doing with some random guy who sidles up to them in the street or puts an ad in their local free paper ( if they still have one). It's like just logging on to the site hypnotises them.
Easy best fix: stop using failbook. (not really all that easy for some people, I understand, but still...
The critical link
It that Facebook was unwilling so far to block the domains they were using to bury their abusive links. Those services are largely unnecessary for page navigation and rendering. The industry is mostly built on shady operators juggling link clicks around to pump up their ad auctions.
We really SHOULD just blackhole these outfits, which will inconvenience legitimate operators, but knock out whole tracks of bad actors. An internet without these companies would be a better internet.