Cyberattackers Abuse Facebook Ad Manager in Savvy Credential-Harvesting Campaign

Spread the love


Attackers are piggybacking on the power of the Facebook brand by using emails that look like they’re coming from Facebook Ads Manager. The idea is to lure victims into coughing up credentials and credit card information on a Facebook lead generation form.

According to a Tuesday report by the security research team at Avanan, attackers are sending phishing messages that appear to be urgent warnings from Meta’s “Facebook AdManager” team. The messages claim the victim is not complying with the company’s ad policies and that the ad account will be disabled if the target doesn’t appeal the phony violation.


The Facebook Ads phishing message. Source: Avanan

The “appeal form” link leads to a credential harvesting site that uses a real Facebook lead-generation form to collect passwords and credit card information.

Abusing the Facebook Ads System

An interesting aspect to the campaign is that rather than using a harvesting site hosted on a sketchy IP somewhere, attackers are gaming the Facebook ads system to create lead-generation forms with malicious intent. Doing so kills two birds with one stone: First of all, it fools a lot of automated checks for malicious links used by email platforms. Using legitimate sites is what the Avanan team refers to as the Static Expressway.

“Hackers are leveraging sites that appear on static Allow Lists,” explained Jeremy Fuchs, cybersecurity researcher for Avanan, in the report. “That means that email security services have broadly decided that these sites are trustworthy, and thus anything related to them comes through to the inbox.”

See also  TikTok Begins Legal Defense Against US Sell-Off Bill

Additionally, using Facebook Ads forms also offers a high degree of verisimilitude for any of the eight billion advertising users that Facebook works with who are already familiar with the Ads Manager platform and the lead-generation forms it produces.

“For the end user, seeing that their Facebook ad account has been suspended is cause for concern,” Fuchs said. “Since it’s a legitimate Facebook link, the user would feel confident continuing on.”

Tell-Tale Signs of ‘Brandjacking’

Fuchs wrote that while the sites used in this credential harvesting campaign appeared to be legitimate, there is a red flag in the phishing messages they uncovered: Typically, these are coming from Outlook accounts such as [email protected]

Additionally, the physical address footer in the emails are wrong. But if users didn’t notice these details, they could easily be foiled by this ploy.

According to research released earlier this year, brand impersonations, or brandjackings, like these increased by 274% last year as attackers continue to peddle their scams by looking like they come from reliable sources. Facebook is a particular favorite among phishers to impersonate. A report released by Vade this spring found Facebook was the No. 1 impersonated brand last year, edging out perennial favorite Microsoft for the top spot.

According to Abnormal Security research detailing data from the first half of 2022, email attacks increased by 48% in that timeframe, with more than 1 in 10 attacks impersonating well-known brands. Some 256 individual brands were impersonated, with LinkedIn and Microsoft appearing to be the favorites so far in 2022.

best barefoot shoes

Source link

  • David Bridges

    David Bridges

    David Bridges is a media culture writer and social trends observer with over 15 years of experience in analyzing the intersection of entertainment, digital behavior, and public perception. With a background in communication and cultural studies, David blends critical insight with a light, relatable tone that connects with readers interested in celebrities, online narratives, and the ever-evolving world of social media. When he's not tracking internet drama or decoding pop culture signals, David enjoys people-watching in cafés, writing short satire, and pretending to ignore trending hashtags.

    Related Posts

    Elon Musk Warns Rival ISPs of Upcoming Challenges

    Spread the love

    Spread the love Share It: ChatGPT Perplexity WhatsApp LinkedIn X Grok Google AI Elon Musk’s Warning to Competing ISPs: Expect More Challenges Ahead  Broadband Breakfast You can access the original article…

    Read more

    AI May Soon Provide Personal Superintelligence to All Investors

    Spread the love

    Spread the love Share It: ChatGPT Perplexity WhatsApp LinkedIn X Grok Google AI Mark Zuckerberg Claims AI Could Soon Provide “Personal Superintelligence for All” Right Before Meta Experienced a 91%…

    Read more

    You Missed

    Elon Musk Warns Rival ISPs of Upcoming Challenges

    Elon Musk Warns Rival ISPs of Upcoming Challenges

    Money Robot Submitter Review 2026: Is This Backlink Automation Tool Worth It?

    Money Robot Submitter Review 2026: Is This Backlink Automation Tool Worth It?

    Mexican Influencer Killed by Motorcycle Gunman During Live Stream

    Mexican Influencer Killed by Motorcycle Gunman During Live Stream

    PUNCH Mission by NASA Predicts Solar Storms Impact on Earth

    PUNCH Mission by NASA Predicts Solar Storms Impact on Earth

    AI May Soon Provide Personal Superintelligence to All Investors

    AI May Soon Provide Personal Superintelligence to All Investors

    Second Degree Murder Charge After Fight Incident

    Second Degree Murder Charge After Fight Incident

    Twitter Reacts to Albert Pujols’ MLB Pitching Debut

    Twitter Reacts to Albert Pujols’ MLB Pitching Debut

    AI Hacking Reports: This One Seems Serious and Alarming

    AI Hacking Reports: This One Seems Serious and Alarming

    Release Date and Cast Insights – Hollywood Life

    Release Date and Cast Insights – Hollywood Life

    Shawn Mendes and Bruna Marquezine Go Instagram Official

    Shawn Mendes and Bruna Marquezine Go Instagram Official