Hackers have created a vast network of fake and compromised Facebook accounts to send millions of phishing messages via Messenger to users managing business accounts. According to a new report from Guardio Labs, the goal is to infect these accounts with malware that steals passwords.

Attackers try to convince targets to download a RAR/ZIP, which contains a downloader for a Python-based stealer malware that steals cookies and passwords stored in the victim's browser.
Facebook Messenger: Phishing attack
Hackers begin the attack on Messenger by sending phishing messages to Facebook business accounts. These messages refer to alleged copyright infringement or request more information about a specific product
The attached file contains a batch file that, if executed, retrieves a malware dropper from GitHub repositories to evade blocklists.
See also: Ducktail hacking group targets Facebook Business Accounts with malvertising
Along with the payload (project.py), the batch script also retrieves a standalone Python environment required by the information-stealing malware. In addition, it achieves persistence by setting the stealer binary to run at system.
The project.py has five levels of obfuscation to make it more difficult to detect.
The malware collects all cookies and login data stored in the victim’s browser. It places them in a ZIP file named “Document.zip” and sends it to the hackers via Telegram or Discord bot API.
Finally, the malware deletes all cookies from the victim's device to log them out of their accounts, giving hackers time to steal the newly compromised account by changing the passwords.
Until social media companies respond to user requests regarding compromised accounts, hackers have time to conduct fraudulent activities with those accounts.
See also: Microsoft Teams: Phishing attack pushes DarkGate malware
Researchers at Guardio Labs have observed that the Messenger phishing campaign targeting Facebook business accounts is massive. The researchers report around 100,000 phishing messages per week, sent primarily to users in North America, Europe, Australia, Japan, and Southeast Asia.
Guardio Labs reports that the scale of the attack is such that approximately 7% of business accounts on Facebook have been affected, with 0.4% having downloaded the malicious file.
However, to be infected with the malware, users must execute the batch file. Therefore, the number of accounts compromised is unknown.

Vietnamese hackers
Researchers attribute this campaign to Vietnamese hackers due to some elements of the password-stealing malware and the use of the “ Coc Coc ” browser , which is popular in Vietnam.
Hackers from Vietnam have targeted Facebook accounts again this year. They have been stealing accounts and selling them via Telegram or dark web marketplaces.
See also: Google Looker Studio abused in cryptocurrency phishing attacks
In May 2023, Facebook announced that it had disrupted a campaign originating from Vietnam that developed a new information-stealing malware called “NodeStealer.”
Messenger phishing tactics are proving to be extremely effective, as users often trust incoming messages, especially when they appear to come from familiar communications or official business accounts. Hackers exploit this trust, using sophisticated techniques to trick users into downloading malicious software. It is important for users to always be cautious of the messages they receive and to make sure that any attachments or links sent to them are safe before downloading.
Source: www.bleepingcomputer.com
