Stay alert! An advanced phishing attack has been detected, where Facebook posts are used to lure unsuspecting users to reveal their login credentials and their PII. Do not fall into the trap of this malicious strategy – protect yourself from the threat of identity theft by keeping your data secure.
See also: Meta threatens to take down news from Facebook

Emails are sent to targets claiming falsely that there is a copyright infringement on one of their Facebook posts, threatening to deactivate the account within 48 hours if no action is taken.

The account deletion review link is an actual Facebook post on facebook.com, which helps threat actors bypass email security solutions and ensure that their phishing messages are delivered to the inbox .
The Facebook post pretends to be “Page Support,” using a Facebook logo – so it appears as if it is managed by the company.
See also: Facebook's oversight system favors "business partners"

However, this post includes a malicious link intended to deceive the public. The external phishing site bears the name of Meta, Facebook's parent company, to conceal the scam and increase the naivety of unsuspecting victims.
Trustwave analysts identified the following three URL addresses that remain active at the time, which were used in a phishing campaign.
- meta[.]forbusinessuser[.]xyz/?fbclid=123
- meta[.]forbusinessuser[.]xyz/main[.]php
- meta[.]forbusinessuser[.]xyz/checkpoint[.]php
The phishing sites are carefully crafted to appear like Facebook's real copyright complaint page, containing a form asking victims to enter their full name , email address , phone number , and Facebook username

In addition to the data it collects, this page also records the IP address and location of each victim who submits information, before sending it all to a Telegram account controlled by the malicious actor.
Threat actors may collect additional information to bypass fingerprint protections or security questions while taking over the victim's Facebook account.
See also: How to contact Facebook to report a bug
Meanwhile, a redirection takes the victim to the next phishing page, which displays a fake 6-digit one-time password (OTP) request with a timer.

Any code entered by the victim will result in an error. If the user clicks ‘Need another way to authenticate?’, the site redirects to the real Facebook site.
Trustwave analysts observed that malicious actors were using Google Analytics on phishing websites to evaluate the success of their campaigns.
Common practice
According to Trustwave, countless Facebook accounts have been discovered with fraudulent posts that masquerade as support pages and redirect victims to malicious phishing sites.

To avoid detection, these posts use URL shorteners to direct unsuspecting users to malicious phishing websites.
Unsuspecting victims may encounter these posts via electronic “phishing” messages, as in the campaign discussed in this report, or via messages on Facebook.
Phishing attacks are difficult to detect because they often appear legitimate at first glance. It is important that everyone takes precautions when accessing their online accounts and remains vigilant for suspicious emails or messages that could be part of a phishing attack.
Information source: bleepingcomputer.com
