Researchers have uncovered a large-scale phishing campaign that abused Facebook and Messenger to lure millions of users to phishing pages, tricking them into entering their account credentials and viewing ads.
The campaign operators used these stolen accounts to send further phishing emails to their friends, generating significant revenue through online advertising.
According to PIXM , a New York-based cybersecurity firm focused on artificial intelligence , the phishing campaign peaked on Facebook in April-May 2022 , but had been active since at least September 2021. PIXM was able to identify the threat actor and map the campaign because one of the identified phishing pages hosted a link to a traffic monitoring application (whos.amung.us) that was publicly accessible without authentication.
While it is unknown how the campaign initially began, PIXM reports that victims were reached by phishing landing pages from a series of redirects originating from Facebook Messenger.

See also: Cuba ransomware: New variant detected in recent attacks
As more Facebook accounts were stolen, threat actors used automated tools to send further phishing links to the compromised account's friends, creating a huge increase in stolen accounts.
"A user's account would be compromised and in a likely automated manner, the threat actor would log into that account and send the link to the user's friends via Facebook Messenger," PIXM explains in the report.
While Facebook has safeguards in place to stop the spread of phishing URLs, threat actors have used a trick to bypass these protections.
Phishing emails sent via Facebook used legitimate URL generation services, such as litch.me, famous.co, amaze.co, and funnel-preview.com, which would be a problem to block as legitimate applications use them.

After discovering that they could gain unauthenticated access to the phishing campaign’s statistics pages, the researchers found that in 2021, 2.7 million users had visited one of the phishing portals. That number rose to 8.5 million in 2022, reflecting the massive growth of the campaign. Digging deeper, the researchers identified 405 unique usernames used as campaign identifiers, each with a separate phishing Facebook page. These phishing pages had page views ranging from just 4,000 views to some in the millions, with one of them reaching as many as 6 million page views.

Researchers believe that these 405 usernames represent only a fraction of the accounts used for the campaign.
After the victim enters their credentials on the phishing landing page they clicked on on Facebook, a new cycle of redirects begins, taking them to advertising pages, survey forms, etc. The threat actors receive referral revenue from these redirects, which is estimated to be in the millions of dollars at this scale of operation.
PIXM found a common snippet of code across all landing pages, which contained a reference to a seized website that is part of an investigation against a Colombian identified as Rafael Dorado.

It is unclear who took over the domain and placed the notice on the website.
A reverse whois search revealed links to a legitimate web development company in Colombia and old websites offering Facebook “like bots” and hacking services.
See also: Emotet: Steals credit card information from Chrome users
PIXM shared the results of its investigation with the Colombian Police and Interpol, but as they note, the Facebook phishing campaign is still ongoing, even though many of the identified URLs have been taken offline.
Source: bleepingcomputer.com
