Fraudsters are using a new phishing scheme to trick users into giving up their Facebook credentials, and this time they are exploiting the Facebook page to carry out their attacks.
Fraudsters use Facebook's Apps platform to host malicious content within the Facebook website itself. Attackers sign up for Facebook apps and use the platform's free, wide-ranging features to load malicious web pages via iframes.
The iframes load content from the scammers' server, which is displayed inside the Facebook app, which appears on the Facebook website.
Fraudsters who want to carry out phishing attacks and steal Facebook only need some CSS skills to create a login form that uses Facebook's default UI style.
Users who reach these pages through various e-mail or social spam campaigns will have a very difficult time realizing that this is a malicious page.
All the other Facebook elements are there and everything is fully functional. The Facebook menu works, the notifications show real Facebook notifications, and the page URL is the real Facebook address.
The only difference is the malicious iframe in the middle of the page, loaded by the Facebook Apps from the scammers' server. In this particular campaign, detected by security firm Netcraft, this iframe was loaded from a malicious website hosted on HostGator.
In case some smarter users suspect something, a peculiarity of the campaign makes sure to fool even those who have undergone anti-phishing training, which tells users to incorrectly enter their login credentials into suspicious login forms.
Users who log in with incorrect login details and eventually see the login success message are certainly convinced that the login form is fake and that someone is trying to trick them.
As a peculiarity of this campaign identified by Netcraft, the login form always showed a login error whenever the user tried to pass authentication, even if correct or incorrect credentials were entered.
Using this trick, some low-end CSS skills, social engineering, and the Facebook Apps platform, scammers can create effective phishing campaigns directly from the official Facebook.
To maintain account security, users should be very cautious when entering their Facebook login credentials into internal Facebook apps (hosted on apps.facebook.com domains). Facebook automatically authenticates all its users within these apps; everyone should always use the facebook.com/login URL to authenticate on the site and nowhere else.



