Full Report
Group-IB uncovers more than 2,400 scam job pages in ongoing campaign targeting users in Egypt, KSA, Algeria, and 10 other MEA countries.
Analysis Summary
# Incident Report: Massive Job Scam Campaign Targeting MEA Region
## Executive Summary
Group-IB uncovered a large-scale scam campaign involving over 2,400 fraudulent job pages impersonating well-known brands. The campaign primarily targeted users in the Middle East and Africa (MEA) region, including Egypt, Saudi Arabia, and Algeria, to steal personal information and social media credentials. The threat actors utilized social media advertising and automated bots to lure victims into a multi-stage phishing funnel.
## Incident Details
- **Discovery Date:** January 2024 (Reporting date)
- **Incident Date:** Ongoing (Campaign active through 2023-2024)
- **Affected Organization:** Over 2,400 spoofed pages impersonating various MEA brands.
- **Sector:** Cross-sector (targets include Retail, Government, and Energy).
- **Geography:** Egypt, Saudi Arabia (KSA), Algeria, and 10 other MEA countries.
## Timeline of Events
### Initial Access
- **Date/Time:** Ongoing campaign.
- **Vector:** Social Media Advertising (Facebook).
- **Details:** Scammers created fake social media profiles and paid advertisements featuring high-salary job vacancies to attract job seekers.
### Lateral Movement
- **Details:** N/A. This was an external phishing campaign targeting consumers rather than a corporate network breach. However, the scammers utilized redirect chains to move users from social media platforms to external phishing domains.
### Data Exfiltration/Impact
- **Details:** Users were coerced into providing full names, phone numbers, and most critically, login credentials for social media platforms (specifically Facebook) via fake login prompts.
### Detection & Response
- **How it was discovered:** Group-IB's Digital Risk Protection (DRP) team identified a massive cluster of related fraudulent domains using AI-powered scanning.
- **Response actions taken:** Group-IB initiated its three-phase takedown process to block fraudulent domains and alerted the public through threat intelligence reporting.
## Attack Methodology
- **Initial Access:** Social Engineering via fake job advertisements on social media.
- **Persistence:** Use of legitimate-looking domain names and hijacked social media accounts to maintain a veneer of authenticity.
- **Privilege Escalation:** N/A (Direct credential theft).
- **Defense Evasion:** Use of URL shorteners, multiple redirects, and localized content (Arabic) to bypass generic security filters.
- **Credential Access:** Phishing pages mimicking official social media login portals.
- **Discovery:** Scammers used automated bots to distribute links across social media comments and groups.
- **Lateral Movement:** N/A.
- **Collection:** Forms gathering PII (Personally Identifiable Information).
- **Exfiltration:** Data sent to attacker-controlled C2 (Command and Control) servers via web forms.
- **Impact:** Financial loss for individuals, identity theft, and significant brand damage to impersonated companies.
## Impact Assessment
- **Financial:** High potential for individual loss; costs to companies for brand remediation and legal action.
- **Data Breach:** Exposure of PII and account credentials for thousands of users across 13 countries.
- **Operational:** Minimal for the impersonated companies, but high for the security teams managing the takedowns.
- **Reputational:** Significant; impersonated brands face loss of trust from consumers who fell victim to the scam.
## Indicators of Compromise
- **Network indicators:** Over 2,400 domains identified (e.g., `job-offers-mea[.]com`, `career-portal-egypt[.]net` - *Examples defanged*).
- **Behavioral indicators:** Redirections from Facebook ads to non-official domains; requests for social media passwords to "apply" for a job.
## Response Actions
- **Containment measures:** Domain blacklisting and reporting of fake social media profiles.
- **Eradication steps:** Proactive takedown requests sent to domain registrars and hosting providers.
- **Recovery actions:** Public awareness campaigns and advising victims to reset credentials and enable MFA.
## Lessons Learned
- **Key takeaways:** Scammers are increasingly leveraging the "Job Search" anxiety in specific economic regions to harvest data.
- **What could have been done better:** Earlier cross-platform sharing of ad-fraud data between social media companies and cybersecurity firms could have reduced the campaign's lifespan.
## Recommendations
- **For Users:**
- Verify job openings on the company’s official "Careers" page.
- Be wary of "too good to be true" salaries.
- Enable Two-Factor Authentication (2FA) on all social media and email accounts.
- Check for typosquatting (e.g., `brand-jobs[.]com` vs `brand.com`).
- **For Companies:**
- Deploy Digital Risk Protection (DRP) tools to monitor for brand impersonation.
- Establish a clear procedure for reporting scams to your customers.
- Proactively monitor social media for unauthorized use of corporate logos and trademarks.