Facebook users are being targeted by a malicious campaign that uses hundreds of fake Facebook Ads to steal credit card information.

They use brand misrepresentation and false advertising strategies to achieve their goals.
Recorded Future's Payment Fraud Intelligence team identified this campaign on April 17, 2024 and named it ERIAKOS, due to its use of the same content delivery network (CDN) oss.eriakos[.]com.
Read more: Hackers use fake Facebook ads to distribute malware
"These fake sites were accessible exclusively through mobile devices and advertising bait, a tactic aimed at evading automated detection systems," the company said, noting that the network included 608 fake websites.
Some of these fake Facebook Ad baits rely on offers to entice users to click. According to Recorded Future, up to 100 Meta associated with a scam website can be displayed in a single day.
The fake sites and Facebook Ads primarily attempt to imitate a major online e-commerce platform and a power tool manufacturer, while also targeting victims with fake sales offers for well-known brand products. Another critical tactic used by hackers involves the use of fake user reviews on Facebook to attract potential victims.
“The merchant accounts and associated domains linked to the scam sites are registered in China. This suggests that the entities involved in this campaign have likely set up the business they use to manage the scam accounts in the country,” Recorded Future noted.
This is not the first time that criminal e-commerce networks have emerged with the aim of collecting credit card information and making illegal profits from fake orders. In May 2024, a vast network of 75,000 fake online stores, known as BogusBazaar, was uncovered, which had generated over $50 million from advertising designer shoes and clothing at extremely low prices.
See more: Google ads: Malicious ads promote fake chat apps
Last month, Orange Cyberdefense uncovered a previously undocumented traffic direction system (TDS) called R0bl0ch0n TDS, which is used to promote affiliate marketing scams through a network of fake store survey and sweepstakes websites, with the aim of collecting credit card information.
"Several different actors are used to initially propagate URLs redirected via R0bl0ch0n TDS, indicating that these campaigns are likely being carried out by different affiliates," security researcher Simon Vernin reported.
This revelation comes as fake Google Ads have been spotted appearing when searching for Google Authenticator and redirecting users to a deceptive website (“chromeweb-authenticators[.]com”). This website offers a Windows executable hosted on GitHub and ultimately installs an information stealer called DeerStealer.
What makes the ads seem legitimate is that they appear to come from “google.com,” with the advertiser’s identity verified by Google. As Malwarebytes reports, “an unknown individual was able to impersonate Google and successfully promote malware disguised as a branded Google product.”
Additionally, malicious advertising campaigns have been detected spreading various other malware, including SocGholish (also known as FakeUpdates), MadMxShell, and WorkersDevBackdoor. Malwarebytes’ analyses reveal common infrastructure factors between the latter two, indicating that they likely originate from the same threat actors.

Read also: Xiaomi: Will it remove System Ads?
Additionally, advertisements for Angry IP Scanner have been used to lure users to fake websites. The email address “goodgoo1ge@protonmail[.]com” has been used to register domains hosting both MadMxShell and WorkersDevBackdoor.
“Both of these malware have the ability to collect and steal sensitive data, while also providing a direct entry route for the initial access brokers involved in ransomware,” said security researcher Jerome Segura.
Source: thehackernews
