Friday, September 11, 2026

New ClickFix Campaign Exploits Fake Verification Pages to Hijack Facebook Sessions

A sophisticated ClickFix campaign targeting Facebook users has been identified, leveraging social engineering to extract live session credentials directly from victims’ browsers.

Unlike traditional phishing exploits that rely on software vulnerabilities, this campaign guides victims through a guided credential-harvesting process disguised as account verification.

Researchers identified 115 webpages across the attack chain and eight distinct exfiltration endpoints, primarily targeting creators, monetized pages, and businesses seeking verification badges.

The campaign initiates with a fake Facebook verification or appeal page promising free verified badges or account recovery assistance.

Victims are presented with animated verification sequences that create legitimacy before being redirected to second-stage pages impersonating the “Facebook Blue Tick Center.”

Here, attackers introduce instructional videos explicitly guiding victims to extract session tokens (c_user and xs values) from their browser’s developer tools and cookie storage.

Once victims submit these session credentials, real-time JavaScript validation ensures only valid Facebook tokens are accepted, reducing attacker-side noise.

Unit42 first highlighted this campaign on December 19, 2025, while infrastructure analysis reveals related phishing pages have been active since January 2025.

The validated tokens are immediately exfiltrated via JSON POST requests to third-party collection endpoints like submit-form[.]com, Formspark, and shiper[.]app.

Instead of a fake login page, the flow starts with a badge or appeal pretext and pushes victims into submitting session tokens from their browser.

If the session token cannot be replayed, the workflow falls back to harvesting security backup codes and passwords through subsequent phishing pages.

Infrastructure and Collection

The attackers employ a multi-layered infrastructure strategy to maintain resilience. Phishing pages are hosted across abuse-friendly platforms, including Netlify, Vercel, Wasmer, GitHub Pages, Surge, Cloudflare Pages, and Neocities enabling rapid redeployment when pages are taken down.

The results show 8 unique titles from IoCs with a 200 status code in the Hunt.io Platform (Source : Hunt.io).
The results show 8 unique titles from IoCs with a 200 status code in the Hunt.io Platform (Source : Hunt.io).

Exfiltration is decoupled from hosting through serverless form backends, allowing attackers to separate visible phishing infrastructure from data collection endpoints.

Analysis reveals extensive infrastructure reuse through page-title pivots. A single title like “Facebook Security Confirmation” appears across 14 distinct URLs, while 103 unique hostnames serve Facebook verification-themed content since January 2025.

Hostname naming conventions show strong clustering around “blue tick,” “verified badge,” “appeal,” and “free verification,” indicating centralized content templates and coordinated operations.

Second-stage phishing page impersonating the "Facebook Blue Tick Center" using Facebook branding (Source : Hunt.io).
Second-stage phishing page impersonating the “Facebook Blue Tick Center” using Facebook branding (Source : Hunt.io).

Advanced variants introduce environment-profiling logic to dynamically branch the attack flow based on victim geolocation and proxy status.

One observed variant queries https://handle[.]gadgetsdecory[.]xyz:3000/anotherdc to profile IP intelligence, geolocation, and proxy usage.

Non-proxy users outside Pakistan receive different instructional videos and expanded harvesting workflows, including direct email-based exfiltration to hardcoded attacker inboxes ([email protected], [email protected], [email protected]).

Commented-out code reveals additional operator identities including “sajjad boss,” “sajjad,” and “waseem,” suggesting a small but organized threat group managing multiple attack chains simultaneously.

Defense Implications

This campaign demonstrates why ClickFix attack remains highly effective: it bypasses the need for software exploits entirely, relying instead on social engineering and trust manipulation.

The Meta page is designed to create urgency by warning users that their account or page is scheduled for deletion due to violations of community guidelines.

Fake Meta policy violation notice designed to create urgency by warning victims that their page is scheduled for deletion unless an appeal is submitted (Source : Hunt.io).
Fake Meta policy violation notice designed to create urgency by warning victims that their page is scheduled for deletion unless an appeal is submitted (Source : Hunt.io).

The “verification” narrative creates urgency and legitimacy, convincing users to surrender authenticated session access voluntarily the most valuable asset for account takeover.

Defenders should prioritize monitoring serverless form backends and collection endpoints rather than individual phishing pages.

Pages requesting c_user and xs values, especially when framed as “verification,” “appeal,” “badge,” or “security confirmation,” should trigger immediate alerts.

Tracking abuse-friendly hosting patterns and pivoting on reused page titles enables reliable expansion of campaign infrastructure.

With stolen sessions enabling immediate account takeover, rapid detection and collection endpoint blocking remain critical for reducing attacker success.

Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

OpenMatter Network Realigns Leadership Team to Accelerate Global Commercial Growth

Melbourne, Florida, September 10th, 2026, CyberNewswire With its Verification Architecture...

Hackers Can Turn Vulnerable LiteLLM AI Gateways Into Root Access and Cloud Credential Theft

Nearly one in 10 internet-exposed LiteLLM AI gateways accepted...

Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Microphone

Skullcandy Dime 3 wireless earbuds have a serious vulnerability...

Hackers Steal Active Directory Password Hashes Without Attacking Domain Controllers Directly

Threat actors are increasingly exploiting Active Directory replication mechanisms...

Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers

Threat actors are exploiting anticipation around Grand Theft Auto...

Apple Xcode Integer Underflow Flaw Lets Crafted Archives Leak Memory and Crash Builds

A recently disclosed integer-underflow vulnerability in Apple’s modern Mach-O...

Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root

Palo Alto Networks has announced a high-severity buffer overflow...

New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners

A phishing campaign that moves the credential-harvesting page out...

Related Articles

Recent News