Full Report
Group-IB Digital Risk Protection discovers more than 3,200 fake Facebook profiles in ongoing phishing campaign that sees scammers impersonate Meta support staff
Analysis Summary
# Tool/Technique: Meta-Impersonation Phishing Campaign
## Overview
This is an ongoing large-scale social engineering and phishing campaign targeting Facebook users. The attackers impersonate Meta (Facebook’s parent company) support staff to deceive users into providing their account credentials. The campaign utilizes thousands of fake profiles and sophisticated redirection tactics to bypass security filters and appear legitimate.
## Technical Details
- **Type:** Phishing / Credential Theft
- **Platform:** Web-based (Social Media / Facebook)
- **Capabilities:** Credential harvesting, brand impersonation, automated redirection, bypassing platform security filters.
- **First Seen:** Reported by Group-IB in February 2024 (Campaign involves over 3,200 fake profiles).
## MITRE ATT&CK Mapping
- **[TA0001 - Initial Access]**
- **[T1566.002 - Phishing: Spearphishing Link]**
- **[TA0007 - Discovery]**
- **[T1589.001 - Gather Victim Identity Information: Credentials]**
- **[TA0005 - Defense Evasion]**
- **[T1221 - Template Injection / Use of legitimate branding]**
- **[T1564 - Hide Artifacts (Use of redirects/shortened URLs)]**
## Functionality
### Core Capabilities
- **Impersonation:** Creation of over 3,200 fake profiles using Meta/Facebook official logos and naming conventions (e.g., "Meta Support," "Security Page").
- **Social Engineering:** Sending messages to victims claiming their account has violated community standards or is scheduled for deletion to create a sense of urgency.
- **Credential Harvesting:** Hosting fake login portals that mimic the Facebook login UI to capture usernames and passwords.
### Advanced Features
- **Redirection Chains:** Use of multiple redirect layers to obfuscate the final phishing destination from automated security crawlers.
- **Typosquatting:** Registration of domains that closely resemble official Meta or Facebook domains.
- **Subdomain Abuse:** Leveraging subdomains to make malicious URLs appear as if they belong to a trusted parent domain.
## Indicators of Compromise
- **File Hashes:** N/A (Web-based campaign)
- **File Names:** N/A
- **Registry Keys:** N/A
- **Network Indicators:**
- Over 3,200 fake Facebook profiles (identified by Group-IB).
- Phishing domains often containing keywords like "meta-support," "fb-security," or "account-verification" [defanged: meta-support[.]com, fb-help-center[.]net].
- **Behavioral Indicators:**
- Unexpected private messages from accounts claiming to be "Meta Support."
- Directing users to external websites to "verify" account status.
## Associated Threat Actors
- **Groups:** Currently unattributed (Ongoing investigation).
## Detection Methods
- **Signature-based detection:** Monitoring for known phishing URLs and blacklisted domains associated with the campaign.
- **Behavioral detection:** Identifying accounts that exhibit high-frequency messaging patterns with links to external domains not belonging to the official Meta infrastructure.
- **Digital Risk Protection:** Using automated tools to scan for unauthorized use of corporate logos and brand assets across social media platforms.
## Mitigation Strategies
- **Multi-Factor Authentication (MFA):** Enabling 2FA (TOTP or Hardware keys) to ensure stolen passwords alone are insufficient for account access.
- **URL Verification:** Training users to inspect the top-level domain (TLD) and look for typosquatting.
- **Security Awareness Training:** Educating employees and users that Meta support will never request passwords via private messages or external links.
- **Brand Monitoring:** Implementing Digital Risk Protection (DRP) to automatically detect and take down fraudulent profiles.
## Related Tools/Techniques
- **Typosquatting:** Registering domains similar to popular sites.
- **Brand Protection Spoofing:** Using the victim's trust in a platform's own security team to lower their defenses.