Clickbait to Catastrophe: How a Fake Meta Email Leads to Password Plunder

March 21, 2025, 2:44 p.m.

Description

A sophisticated phishing campaign targeting Meta Business accounts has been uncovered by the Cofense Phishing Defense Center. The attack begins with a fake Instagram alert claiming the user's ads are suspended due to policy violations. Victims are directed to a fraudulent page mimicking Meta's business help center, where they're prompted to interact with a fake chat support or follow step-by-step instructions. The ultimate goal is to trick users into adding the attacker's device as a secure login method via Two-Factor Authentication, effectively hijacking the account. The campaign employs convincing email templates, landing pages, and even includes live agent support to add credibility. Users are urged to verify communications and examine URLs carefully before taking action to protect their social media credentials.

Date

  • Created: March 21, 2025, 10:33 a.m.
  • Published: March 21, 2025, 10:33 a.m.
  • Modified: March 21, 2025, 2:44 p.m.

Indicators

  • http://businesshelp-manager.com/chat.php?id=
  • http://link.engagezc.com/b/DthfdUh51xpmxoZc44di0w~~.PZmcCYg1oTEvcB_7uzh1T49cj3sB.gAE5JmtFTr7FkJogNps2nA~~?q=hXXps%3A%2F%2Fbusinesshelp-manager.com%2F#user_email=
  • businesshelp-manager.com
  • link.engagezc.com
  • 2fbusinesshelp-manager.com

Attack Patterns

  • T1534
  • T1185
  • T1204
  • T1566
  • T1078

Additional Informations

  • Media

Linked vulnerabilities