Security researchers have uncovered a massive phishing campaign using Facebook ads and GitHub pagesto target more than 615,000 users, stealing credentials their account

Facebook: Ads Phishing campaign
Researchers from Nepalese cybersecurity firm Threat Nixhave published their findings on a widespread phishing campaign on Facebook. According to the research, the attackers targeted Facebook users with fake ads. Such ads usually appear as sponsored posts from pages owned by various companies and vendors.
Users usually have no problem with these sponsored posts and often click on the ads to learn more .Attackers exploit users' interest and created this campaign to deceive them.
According to researchers, the criminals created several pages that impersonate other legitimate company sites. These pages run sponsored ads with links that redirect users to phishing pages hosted on GitHub pages.
Phishing sites ' credentials users.
Security researchers have published an example of such an ad. The ad purports to be from Nepal Telecom and claims to offer free GB to users. Users are asked to click on a shortened URL.

But how did the attackers manage to successfully carry out this phishing campaign?
The researchers explain: “While Facebook takes steps to ensure that such phishing pages are not approved for advertising, in this case, the scammers were using Bitly links that should have initially pointed to a legitimate page. After the ad was approved, the links were modified to lead to a phishing domain.”
The phishing campaign mostly affected users from Asia
According to statistics, the campaign mainly targeted Asian users, however, the overall impact also reached Africa and Europe. Mostly, the victims came from Nepal, Philippines, Egypt, Pakistan, Mongolia, Norway, Tunisia, Iraq, Malaysia and Algeria. However, the list showed stolen credentials from users from more than 50 countries.
By the time of discovery, the campaign had already targeted more than 615,000 users and was ongoing. At this time, researchers have not shared further details as they work to take down this ads phishing campaign.
Source: Latest Hacking News
