HomeSecurityMessenger: Malicious chatbots steal credentials for Facebook pages

Messenger: Malicious chatbots steal credentials for Facebook pages

A new phishing uses a Facebook Messenger chatbot and impersonates the company's support team with the aim of stealing credentials used to manage Facebook pages.

Facebook Messenger chatbot

Chatbots are programs that impersonate humans in the support department and are typically used to provide answers to simple questions or to evaluate cases before they are handed over to a regular employee.

See also: AMD investigates allegations of hacking and theft of company data

TrustWave researchers have discovered a new phishing campaign that uses Facebook Messenger chatbots to steal credentials of users who manage Facebook pages.

Chatbots on Facebook Messenger

According to the researchers, the phishing attack begins with an email informing the recipient that their Facebook page has violated the Community Standards. The message states that the user has 48 hours to appeal the decision. Otherwise, their page will be deleted.

Facebook credentials

The email also says that the user can resolve the issue by contacting Facebook’s Support Center. The email “facilitates” access to the support center by telling the user to click a “Report Now” button. Clicking this button takes the victim to a Messenger conversation where a chatbot impersonates a Facebook customer support representative.

The persona the user is chatting with is supposedly someone from Facebook’s support team. However, a closer look at the profile that owns the page will reveal that this is not a real support page. The profile being used is just a regular business with zero followers and no posts. While this page may seem unused, it does have a “responds to messages” badge which Facebook defines as having a 90% response rate and replies within 15 minutes. It even featured a Messenger logo as its profile picture to make it look legitimate.

Messenger: Malicious chatbots steal credentials for Facebook pages

The chatbot will send the victim a “Report Now” button in Messenger, which takes victims to a website disguised as a “Facebook Support Inbox.” However, if someone is more observant, they will see that the URL is not part of the Facebook domain.

See also: Raccoon Stealer returns with a new version that steals your passwords

Also, according to TrustWave researchers, the case number on this page does not match the one presented by the chatbot earlier. The attackers do not seem to have paid much attention to these details, as many users may not even notice them. Most likely, they will be panicking and trying to figure out what to do in order not to lose their pages.

The main phishing page, which appears after clicking the button sent by the chatbot in Facebook Messenger, asks users who want to appeal the decision to delete the page to enter their email address, full name, page name, and phone number.

After entering these details and clicking the “Submit” button, a pop-up window appears asking for the password account. After that, all the information is sent to the threat agent’s database via a POST request.

Finally, the victim is redirected to a fake 2FA page where they are asked to enter the OTP they received via SMS.

After verification, victims are taken to a real Facebook page containing intellectual property and copyright instructions, supposedly related to the user's violation.

Because the phishing attack is automated, the actual exploitation of the stolen credentials can happen at a later stage. Obviously, the attackers do not want to arouse suspicion and have made the process look as legitimate as possible. Thus, they hope to delay possible actions to address the breach (e.g. changing credentials, etc.).

The use of chatbots (like here on Facebook Messenger) in phishing attacks for automated credential theft is becoming increasingly common.

See also: NCSC on ransomware: The biggest global cyber threat

It's a clever technique because it helps attackers launch multiple attacks without spending much time or resources. At the same time, chatbots are used by many companies for customer support and thus appear normal. Therefore, this type of fraud is harder to detect.

In any case, do not give out personal information and credentials through online communications and carefully check the addresses of the pages you open to make sure they are official. In addition, you should be very careful with the emails you receive. In this case, the original email could indicate that it is a scam. The sender was called “Policy Issues”, which may have been used to cause panic in the recipient. The sender’s domain did not belong to Facebook, while it was also obvious from the headers and the sender’s IP address that the email was not sent from the social media platform.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS