Full Report
Huntress is tracking a threat actor group as they evolve a phishing attack that uses a Facebook feature to send the initial spam lure.
Analysis Summary
# Threat Actor: Meta Phishers (Untracked Phishing Group)
## Attribution & Identity
* **Actor Identification:** An unknown threat actor group currently being tracked by Huntress and previously documented by Check Point Research.
* **Aliases:** Currently referred to as "Meta Phishers" or the group abusing the "Meta Business Manager partner" mechanism.
* **Associated Groups:** No formal association to known APTs is established in the report, though their infrastructure (Telegram, Google Sites) aligns with contemporary Phishing-as-a-Service (PhaaS) trends.
## Activity Summary
The group has been active since at least November 2025. Their primary operation involves abusing Meta’s legitimate Business Account Manager service to bypass email security filters. By registering as a "Business Manager partner," the actor sends legitimate system-generated emails from `[email protected][.]com`.
In June 2026, the group evolved their tactics to include a chatbot component via Facebook Messenger to automate data collection and increase the perceived legitimacy of the scam.
## Tactics, Techniques & Procedures
* **Legitimate Service Abuse:** Misusing Meta’s "Business Manager partner" request feature to send lures from trusted domains.
* **Lure Manipulation:** Embedding URLs within the "Business Name" field so that automated Meta notifications display the malicious link (e.g., *"Get started [URL]... is not part of or affiliated with Meta"*).
* **Phishing-as-a-Service (PhaaS) Elements:**
* Use of **Google Sites** for initial redirection.
* Use of **Telegram APIs** to exfiltrate stolen data to private channels.
* **Chatbot Integration:** Utilizing fraudulent Facebook Messenger accounts to guide victims through the credential and ID theft process.
* **Credential & Identity Theft:** Capturing MFA codes, personal/business contact info, and photographic proof of identity (passports/IDs).
**MITRE ATT&CK IDs:**
* **T1566.002:** Phishing: Spearphishing Link
* **T1583.001:** Acquire Infrastructure: Domains
* **T1071.001:** Application Layer Protocol: Web Protocols
* **T1071.004:** Application Layer Protocol: DNS (Indirectly via Telegram API)
## Targeting
* **Sectors:** Small and Medium-sized Businesses (SMBs), Social Media Management firms, and Business-to-Business (B2B) services.
* **Geography:** Global, with significant activity noted in the United States.
* **Victims:** Businesses utilizing Meta (Facebook/Instagram) Business Suite for marketing and management.
## Tools & Infrastructure
* **Malware/Tools:** Private Telegram channels for data exfiltration; Facebook Messenger Chatbots.
* **Infrastructure:**
* **Phishing Domains:** `aussiecleaningservices[.]com`
* **Redirectors:** `sites.google[.]com/view/profile1012`
* **Lure Source:** `[email protected][.]com`
* **Exfiltration:** `api.telegram[.]org`
## Implications
This campaign demonstrates the high effectiveness of "living off trusted services." By originating from a legitimate Meta domain, the lures bypass traditional SPF/DKIM/DMARC checks. The shift toward requiring government IDs suggests the actor's motivation extends beyond simple account takeover into full identity theft and potential secondary business compromise (BEC).
## Mitigations
* **Meta Business Settings:** Administrative users should strictly audit "Partner Requests" within the Meta Business Suite and reject any unrecognized entities.
* **Employee Awareness:** Train staff to recognize that legitimate Meta security alerts will never ask for a passport or ID photo via a third-party URL or a chat interface.
* **URL Inspection:** Security teams should monitor for and block unusual Google Sites paths and recently registered domains acting as business proxies.
* **MFA Hardening:** Transition from SMS-based MFA to hardware keys or authenticator apps, as this actor actively phishes for one-time codes.