Cyberattackers Abuse Facebook Ad Manager in Savvy Credential-Harvesting Campaign

Spread the love


Attackers are piggybacking on the power of the Facebook brand by using emails that look like they’re coming from Facebook Ads Manager. The idea is to lure victims into coughing up credentials and credit card information on a Facebook lead generation form.

According to a Tuesday report by the security research team at Avanan, attackers are sending phishing messages that appear to be urgent warnings from Meta’s “Facebook AdManager” team. The messages claim the victim is not complying with the company’s ad policies and that the ad account will be disabled if the target doesn’t appeal the phony violation.


The Facebook Ads phishing message. Source: Avanan

The “appeal form” link leads to a credential harvesting site that uses a real Facebook lead-generation form to collect passwords and credit card information.

Abusing the Facebook Ads System

An interesting aspect to the campaign is that rather than using a harvesting site hosted on a sketchy IP somewhere, attackers are gaming the Facebook ads system to create lead-generation forms with malicious intent. Doing so kills two birds with one stone: First of all, it fools a lot of automated checks for malicious links used by email platforms. Using legitimate sites is what the Avanan team refers to as the Static Expressway.

“Hackers are leveraging sites that appear on static Allow Lists,” explained Jeremy Fuchs, cybersecurity researcher for Avanan, in the report. “That means that email security services have broadly decided that these sites are trustworthy, and thus anything related to them comes through to the inbox.”

See also  Custom AI Lens Feature Added by Snapchat

Additionally, using Facebook Ads forms also offers a high degree of verisimilitude for any of the eight billion advertising users that Facebook works with who are already familiar with the Ads Manager platform and the lead-generation forms it produces.

“For the end user, seeing that their Facebook ad account has been suspended is cause for concern,” Fuchs said. “Since it’s a legitimate Facebook link, the user would feel confident continuing on.”

Tell-Tale Signs of ‘Brandjacking’

Fuchs wrote that while the sites used in this credential harvesting campaign appeared to be legitimate, there is a red flag in the phishing messages they uncovered: Typically, these are coming from Outlook accounts such as [email protected]

Additionally, the physical address footer in the emails are wrong. But if users didn’t notice these details, they could easily be foiled by this ploy.

According to research released earlier this year, brand impersonations, or brandjackings, like these increased by 274% last year as attackers continue to peddle their scams by looking like they come from reliable sources. Facebook is a particular favorite among phishers to impersonate. A report released by Vade this spring found Facebook was the No. 1 impersonated brand last year, edging out perennial favorite Microsoft for the top spot.

According to Abnormal Security research detailing data from the first half of 2022, email attacks increased by 48% in that timeframe, with more than 1 in 10 attacks impersonating well-known brands. Some 256 individual brands were impersonated, with LinkedIn and Microsoft appearing to be the favorites so far in 2022.

best barefoot shoes

Source link

  • David Bridges

    David Bridges

    David Bridges is a media culture writer and social trends observer with over 15 years of experience in analyzing the intersection of entertainment, digital behavior, and public perception. With a background in communication and cultural studies, David blends critical insight with a light, relatable tone that connects with readers interested in celebrities, online narratives, and the ever-evolving world of social media. When he's not tracking internet drama or decoding pop culture signals, David enjoys people-watching in cafés, writing short satire, and pretending to ignore trending hashtags.

    Related Posts

    Twitter Review of Yezhu Kadal Yezhu Malai: 7 Must-Read Tweets

    Spread the love

    Spread the love Share It: ChatGPT Perplexity WhatsApp LinkedIn X Grok Google AI Explore the Yezhu Kadal Yezhu Malai Twitter Review: 7 Essential Tweets to Read Before Watching Nivin Pauly…

    Read more

    AI-Powered Creator Advice in Instagram’s Edits App

    Spread the love

    Spread the love Share It: ChatGPT Perplexity WhatsApp LinkedIn X Grok Google AI Instagram Introduces AI-Enhanced Guidance for Edits App Users  wearetech.africa Access the original article here; all images and photos…

    Read more

    You Missed

    Open-Source SCP Movie to Be Made by Neon Post A24 Controversy

    Open-Source SCP Movie to Be Made by Neon Post A24 Controversy

    Money Robot Submitter Review 2026: Is This Backlink Automation Tool Worth It?

    Money Robot Submitter Review 2026: Is This Backlink Automation Tool Worth It?

    Twitter Review of Yezhu Kadal Yezhu Malai: 7 Must-Read Tweets

    Twitter Review of Yezhu Kadal Yezhu Malai: 7 Must-Read Tweets

    Moneybagg Yo’s Latest Look Has Fans Excited (PHOTOS)

    Moneybagg Yo’s Latest Look Has Fans Excited (PHOTOS)

    AI-Powered Creator Advice in Instagram’s Edits App

    Twitter Review of Yezhu Kadal Yezhu Malai: 7 Must-Read Tweets

    Trump’s ‘Super Intelligence’ Rebrand: A Gift for AI Critics

    Trump’s ‘Super Intelligence’ Rebrand: A Gift for AI Critics

    DAP in Negeri Sembilan Files Police Report on Controversial Post

    Twitter Review of Yezhu Kadal Yezhu Malai: 7 Must-Read Tweets

    Christa Pike Survives Two Lethal Injections

    Christa Pike Survives Two Lethal Injections

    Hurdle Hints and Answers for October 1, 2026

    Hurdle Hints and Answers for October 1, 2026

    Social Media Captures Memories and Promotes Powell Football

    Twitter Review of Yezhu Kadal Yezhu Malai: 7 Must-Read Tweets