City
Epaper

Mega ad phishing campaign hits over 6.15 lakh Facebook users

By IANS | Updated: December 31, 2020 10:20 IST

New Delhi, Dec 31 Cybersecurity researchers have unearthed a large-scale ad phishing campaign that has compromised accounts of ...

Open in App

New Delhi, Dec 31 Cybersecurity researchers have unearthed a large-scale ad phishing campaign that has compromised accounts of more than 6.15 lakh Facebook users from at least 50 countries, by exploiting the pages of open source repository GitHub.

The list of affected users is growing at a rapid pace of more than a 100 entries per minute, according to ThreatNix, a Nepal-based cybersecurity firm.

The researchers first came across the phishing campaign through a sponsored Facebook post that was offering 3GB mobile data from Nepal Telecom and redirecting to a phishing site hosted on GitHub pages.

The page that posted the ad was using the profile picture and name of Nepal Telecom and was almost indistinguishable from the legitimate page.

"We saw similar Facebook posts targeting Facebook users from Tunisia, Egypt, Philippines, Pakistan, Norway, Malaysia etc," the firm claimed in a statement this week.

According to the firm, the ad phishing campaign is using localised Facebook posts and pages spoofing legitimate entities and targeted ads for specific countries.

Links within these posts then redirected to a static Github page website that contained a login panel for Facebook.

"All these static GitHub pages forwarded the phished credentials to two endpoints one to a Firestore database and another to a domain owned by the phishing group," the researchers noted.

"We discovered almost 500 GitHub repositories containing phishing pages that are a part of the same phishing campaign".

Facebook or GitHub was yet to comment on the ThreatNix report.

ThreatNix said that it is working on taking down the phishing infrastructure by collaborating with relevant authorities "as such we are withholding the information related to the domains until then".

While Facebook takes measures to make sure that such phishing pages are not approved for ads, in this case, the scammers were using Bitly link's which initially must have pointed to a benign page and once the ad was approved, was modified to point to the phishing domain, the researchers explained.

( With inputs from IANS )

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Open in App

Related Stories

NationalChandrababu Naidu thanks Prez Murmu, PM Modi after Amaravati gets statutory status as Andhra capital

Other SportsVirat Kohli calls Dhurandhar: The Revenge a ‘cinematic experience’; Aditya Dhar responds with gratitude

EntertainmentVirat Kohli calls Dhurandhar: The Revenge a ‘cinematic experience’; Aditya Dhar responds with gratitude

Entertainment"Was there from beginning, like a silent co-director": Aditya Dhar lauds editor Shivkumar Panicker's work in Dhurandhar's success

EntertainmentAnushka Sharma lauds ‘Dhurandhar 2’: Gripping, immersive, meticulously crafted

Technology Realted Stories

TechnologyKalpakkam nuclear reactor reflects India’s engineering enterprise: PM Modi​

TechnologyBCAS, RRU to establish India’s indigenous aviation security equipment testing centre

TechnologyMinistry of Mines notifies new rules to boost exploration of critical minerals

TechnologySalary hikes in India Inc likely to stay stable at 9.1 pc in 2026

TechnologyIndia’s white-collar job market ends this fiscal strong led by non‑IT, AI hiring