A major phishing scam has been launched and is using Facebook Messenger as its infection vector.

The threat actors behind this campaign are using compromised Facebook accounts to spread links to phishing pages through Facebook Messenger.

Researchers at PIXM first identified this phishing campaign through a fake Facebook login portal that they attempted to visit in September 2021 (shown below)

(Source: Pixm)

How does the scam work?

Fake login pages such as these are common amongst credential harvesting schemes, as they are easy to replicate and look fairly legitimate.

However, this scam has an added layer of deception by utilising compromised Facebook accounts. Using an automated piece of software, the threat actors behind this scam login into compromised accounts, and use it to send links to all of the users’ friends via Facebook messenger.

Similar scams generate posts on compromised accounts that link to fake login pages. Below is an example of such a post found by one of our own researchers:

Facebook’s own internal threat intelligence team will be able to see that these threat actors are utilising Facebook Messenger to harvest credentials. Typically when this occurs the intelligence team will block the link so that any user who mistakenly clicks on it will be prevented from accessing the fake login page.

However, these threat actors have created a technique that prevents their links from being blocked. The link they share is actually a link chain, with the user passing through multiple different, legitimate links before they arrive at the fake web page. As a consequence, Facebook’s internal intelligence team are unable to block the link without blocking legitimate apps and links on their platform, some of which are critical for the platform to function normally.

Because of techniques such as this, one of the only ways to safeguard your organisation from phishing schemes such as this is regular cyber security training of the kind offered by us at TecSec. We can launch a fake and completely safe phishing campaign with your workforce to monitor which of your staff can be tricked by common cyber scams. After this, we will offer a free training module to help any of your staff that have been fooled into clicking a phishing link, to help avoid falling victim to an actual scam in the future. For this free service, fill out our dedicated page here.

If that wasn’t enough, the threat actors also utilise services on popular websites to rapidly deploy and generate new URLs. These new URLs would then be used to create a new link to the fake login page, in the incident that an old link gets blocked. During PIXM’s investigation, the threat actors were utilising my.famous.co. If this link was found and blocked, the threat actors simply used another automated piece of software to generate a new link using the same service, only this time with a new unique ID. As shown below, links to the same fake login page could be blocked repeatedly, and yet the threat actors could generate multiple new links to the page, even on the same day.

(Source: Pixm)

This campaign has been innovative in terms of the methods used by the threat actors behind it to avoid detection. It is no surprise then to discover that in 2021 alone, over 2.7 million Facebook users visited the fake login page.

This number has exploded in 2022, with around 8.5 million users having viewed the page this year so far.

Part of the reason this campaign has had such massive reach is due to the significant number of compromised Facebook accounts utilised by the threat actors. In this campaign, they have used 400 unique usernames that PIXM has been able to identify, but they estimate that this entire campaign uses thousands. Examples of real usernames used can be seen below:

(Source: Pixm)

The average page views for these compromised usernames is 985,228, but as you can see above, some reach as high as 6 million views.

The threat actor

A researcher from the Open Web Application Security Project (OWASP) has managed to get in touch with and partially interview the threat actor behind this campaign. Although it is highly likely the criminal exaggerated his earnings, he stated that he makes roughly $150 for every thousand visits to the fake login page.

A fair estimation of the reach of this campaign is 399,017,673 page views to the login page, meaning that if the scammers’ claim is correct, they will have a projected revenue of $59 million from the fourth quarter of 2021 to the present.

While it is almost certain to be less than that amount, this campaign has certainly yielded several million dollars to the scammer in just a few months.

The revenue is generated from referral revenue which the threat actor fraudulently collects using the compromised accounts. Once the criminal has account details, they can use an automated piece of software to route the “user” of the account to an advertising page. These advertising pages usually require some form of user interaction, such as filling out an online form or even just clicking on the advert. Companies will then see that a user has interacted with the ad, and pay the threat actor a “referral fee” for supposedly increasing the exposure of their brand.

Although this method of generating revenue does not take money directly from the victims of this scam, it is clearly fraudulent and is costing advertising agencies millions.

In the future, it is also highly likely that the threat actor will sell on these compromised accounts. After this other threat actors will likely attempt to deceive contacts on the Facebook account, this time with the intent of taking money from the victims directly.

If your organisation uses Facebook in any capacity, you should be aware of this scam and its potential to affect your staff and all contacts that link to the account.

As mentioned earlier we are currently offering free phishing simulation and a free cyber security training module in order to raise awareness of and protect against scams such as these. To take part, fill in our dedicated form here.