Sunday, April 13, 2025
HomePhishingBeware: Innovative Phishing Threat Targeting Facebook Mobile Users

Beware: Innovative Phishing Threat Targeting Facebook Mobile Users

Published on

SIEM as a Service

Follow Us on Google News

In the past, we came through a number of Phishing campaigns where the attackers using Valid TLD itself for phishing and the Punycode attack demonstrated by Xudong Zheng.

Now hackers find a new way innovative method to create believable URL’s and targeting mobile users, specifically Facebook users.Security experts from Phishlabs came through this new campaign targeting mobile users.

Security expert Crane Hassold says “Instead of attempting to make genuine looking
URLs, threat actors have begun including genuine, legitimate domains within a
longer URL, and padding it with hyphens to hide the real target“.

- Advertisement - Google News

For Example

hxxp://m.facebook.com-------------validate----step1.rickytaylk[dot]com/sign_in.html

You can see the URL starts with m.facebook.com but the real destination URL here is rickytaylk.com, not  m.facebook.com.

Innovative Phishing Threat Targeting Facebook Mobile Users
Source: PHISHLABS

You can see the screenshot, where you can see only the m.facebook.com and an endless stream which hides the original target address.This smart addition of the Facebook favicon in the address bar looks like the site is exceptionally genuine.

Lack of attention

Inattentive mobile users easily fall into the trap and give away their valuable credentials to the attackers. Generally, these phishing URL’s are transferred through SMS, Chats, and Emails.

Here you can see some more examples.

hxxp://login.Comcast.net-------account-login-confirm-identity.giftcardisrael[dot]com/      
hxxp://accounts.craigslist.org-securelogin--------------viewmessage.model104[dot]tv/craig2/  
hxxp://offerup.com------------------login-confirm-account.aggly[dot]com/Login%20-%20OfferUp.htm  
hxxp://icloud.com--------------------secureaccount-confirm.saldaodovidro[dot]com.br/

Crane Hassold says “it’s highly likely that this tactic is being distributed via SMS phishing or through the social messenger, rather than email”.

One can easily identify the Phishing URL that sent through email by just hovering our the link, but that is not possible if the URL provided through SMS.

Security researchers said they have spotted more than 50 attacks of this type and has a rapid growth from last March.

Hackers not using this method for credential harvesting alone, they use to send more phishing URL’s via status updates or private messages.

Common Defence’s against phishing

  • We know logically the organizations like Facebook will not send the login URL through SMS. You should think that before opening.
  • Always make sure that you entering Login credentials and Card details on a HTTPS page.
  • Don’t open the attachments that you are not expecting.
  • Hover the URL to find the URL’s Integrity.
  • It is always better to type the URL directly in the address bar.
Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Threat Actors Manipulate Search Results to Lure Users to Malicious Websites

Cybercriminals are increasingly exploiting search engine optimization (SEO) techniques and paid advertisements to manipulate...

Hackers Imitate Google Chrome Install Page on Google Play to Distribute Android Malware

Cybersecurity experts have unearthed an intricate cyber campaign that leverages deceptive websites posing as...

Dangling DNS Attack Allows Hackers to Take Over Organization’s Subdomain

Hackers are exploiting what's known as "Dangling DNS" records to take over corporate subdomains,...

HelloKitty Ransomware Returns, Launching Attacks on Windows, Linux, and ESXi Environments

Security researchers and cybersecurity experts have recently uncovered new variants of the notorious HelloKitty...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Tycoon 2FA Phishing Kit Uses Advanced Evasion Techniques to Bypass Endpoint Detection Systems

The notorious Tycoon 2FA phishing kit continues its evolution with new strategies designed to...

Chinese eCrime Group Targets Users in 120+ Countries to Steal Banking Credentials

Smishing Triad, a Chinese eCrime group, has launched an extensive operation targeting users across...

GOFFEE Deploys PowerModul in Coordinated Strikes on Government and Energy Networks

The threat actor known as GOFFEE has launched a series of targeted attacks against...