PULSE NAME
Phishing Attack Using Facebook Messenger Chatbots Steal Credentials Used to Manage Facebook Pages
WHITE Informational SVThreatIntel 2022-06-30 Modified: 2022-06-30
5
IOCs
LOW VOLUME
A new phishing attack is using Facebook Messenger chatbots to impersonate the company's support team to steal credentials for managers of Facebook pages. Chatbots in Messenger The attack starts with an email informing that the Facebook page has violated Community Standards, giving 48 hours to appeal the decision, or the page will be deleted. The user is offered a chance to resolve the problem in Facebook’s Support center. To access it, they have to click on an “Appeal Now” button. Clicking the button takes the victim to a Messenger conversation where a chatbot impersonates a Facebook customer support agent.
Indicators of Compromise (5)
All hostname URL
TYPEINDICATORDESCRIPTIONCREATED
hostname appeal-59321958.web.app 2022-06-30
URL https://www.facebook.com/case932571902/ 2022-06-30
URL https://appeal-59321958.web.app/twofac.html 2022-06-30
URL https://appeal-59321958.web.app/pointp.html 2022-06-30
URL https://appeal-59321958.web.app/appeal.html 2022-06-30