HomeSecurityFacebook Messenger: Scammers Target Users in Over 80 Countries

Facebook Messenger: Scammers Target Users in Over 80 Countries

Security researchers at Group-IB have uncovered a scale- fraud campaign targeting Facebook Messenger users around the world. The company’s Digital Risk Protection (DRP) analysts have found evidence that users in more than 80 countries across Europe, Asia, the MEA region (Middle East and Africa), North and South America may have been affected.

By distributing ads promoting a supposedly updated version of Facebook Messenger, cybercriminals are harvesting credentials . Researchers have discovered nearly 1,000 fake Facebook profiles that have been used in this malicious activity. Upon discovering this type of scam, Group-IB notified the social media giant – which has no connection to the fake posts – about the ongoing campaign.

Read also: Facebook: Coding bug allowed attackers to delete live videos

Facebook Messenger Scammers
Facebook Messenger: Scammers Target Users in Over 80 Countries

It is worth noting that this scam was first detected by Group-IB DRP in the summer of 2020 , with DRP analysts from different regions – in Asia and Europe – having identified traces of the same malicious campaign. Since then, the campaign has been growing continuously. In April, the number of Facebook posts urging users to install the “latest Messenger update” reached 5,700 . To attract users’ attention, scammers use accounts with names that “spoof” the real application – Messanger, Meseenger, Masssengar and others – while using the official Facebook Messenger as their profile picture logo .

To bypass fraud filters, scammers use shortened links created with the help of services such as linktr.ee, bit.ly, cutt.us, cutt.ly and rb.gy.After the user clicks on the link that supposedly leads to downloading the updated version of the application, they are taken to a fake Facebook Messenger website with a login form, where they are asked to enter their credentials. Scammers use platforms such as blogspot.com, sites.google.com, github.io and godaddysites.com to register fake Facebook Messenger login pages.

See also: Tech support scammers target Microsoft/McAfee customers with fake subscription renewals

Facebook Messenger Fraudulent Users in Over 80 Countries
Facebook Messenger: Scammers Target Users in Over 80 Countries

In order to entice users to click on the link, the scammers have given the app some non-existent features, such as the ability to find out who visited their profile and see deleted messages or even offered them the option to switch to Gold Messenger. The scammers even use blackmail to force users to download the app, while also threatening them that if they do not register on the fake page, their account will be deleted forever.

Group-IB analysts found “fraudulent” ads targeting users in at least 84 countries worldwide, including Canada, the United States, France, Germany, Italy, Singapore, Malaysia, and South Africa. Users who fall victim to this scam risk having their personal data leaked and their accounts compromised. The scammers, in turn, are likely to use the compromised accounts to either blackmail victims, pushing them to pay a ransom to regain access to their accounts, or further escalate the scheme by using Facebook profiles to distribute fraudulent ads.

Suggestion: Classiscam: Fraudsters "forge" brands and defraud users of European markets!

Facebook Messenger Scammers
Facebook Messenger: Scammers Target Users in Over 80 Countries

Group-IB calls on users to remain vigilant and follow some basic rules of cyber hygiene that will help them not to fall victim to cybercriminals. Users should be especially careful when opening links. In addition, they should never enter personal data on websites they have reached from third-party resources, even if they have logos of well-known brands. They should enter their login credentials only on the official website of the social network/service or in the official application. It is also worth paying attention to the domain of the page they are visiting – scammers often use domain names with spelling errors, as happened with Facebook Messenger.

Information source: securityaffairs.co

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS