Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

New Phishing Attack Targets Facebook Users to Steal Login Credentials

Posted on September 19, 2025September 19, 2025 By CWS

A classy phishing marketing campaign has lately emerged, focusing on Fb customers with rigorously crafted emails designed to reap login credentials.

Attackers leverage the platform’s personal exterior URL warning system to cloak malicious hyperlinks, presenting URLs that seem reliable whereas redirecting victims to counterfeit Fb login pages.

The preliminary lure arrives as an pressing safety notification, warning customers of “unauthorized entry makes an attempt” or prompting them to confirm account exercise.

The e-mail’s design carefully mirrors Fb’s styling, full with social media icons and footer disclaimers, creating a way of authenticity and main recipients to click on with out hesitation.

Phishing (Supply – X)

The marketing campaign’s attain spans a number of languages, together with English, German, Spanish, and Korean, broadening its potential sufferer pool.

Phishing URLs constantly comply with a sample of benign domains forwarded by means of Fb’s redirector service (e.g., httpst.co/MS24b2xu6p), which then reroute to attackers’ infrastructure.

SpiderLabs analysts recognized this system after inspecting dozens of electronic mail samples, noting how the redirect mechanism each evades hyperlink scanners and bypasses consumer suspicion.

Victims who comply with the hyperlink encounter a near-perfect reproduction of Fb’s login interface, the place credentials submitted are instantly exfiltrated to a command-and-control server.

On profitable submission, the faux portal executes a short JavaScript snippet to show an “Incorrect password” error, prompting customers to re-enter their particulars—unwittingly supplying attackers with legitimate credentials on the second try.

The harvested information consists of electronic mail addresses, telephone numbers, and passwords, that are saved in a PHP backend script for later retrieval by risk actors.

Redirect-Primarily based An infection Mechanism

The core innovation of this phishing marketing campaign lies in its abuse of Fb’s exterior URL warning system as an an infection mechanism.

Moderately than linking on to malicious domains, attackers assemble a URL of the shape:-

Confirm Your Account

This hyperlink leverages Fb’s l.fb.com redirect service, embedding the precise phishing web site within the u= parameter.

When clicked, Fb presents a warning banner however finally forwards the sufferer to the malicious web page, lending credibility to the vacation spot.

As soon as on the phishing web site, the HTML type collects credentials by way of:-

Upon submission, a JavaScript routine triggers a second redirect again to Fb, displaying an error discover to the consumer and minimizing suspicion.

This redirect-based an infection mechanism not solely bypasses electronic mail safety gateways but additionally exploits consumer belief in Fb’s area, making detection and prevention considerably tougher.

Discover this Story Fascinating! Observe us on Google Information, LinkedIn, and X to Get Extra Immediate Updates.

Cyber Security News Tags:Attack, Credentials, Facebook, Login, Phishing, Steal, Targets, Users

Post navigation

Previous Post: Unpatched Vulnerabilities Expose Novakon HMIs to Remote Hacking
Next Post: Russian Hackers Gamaredon and Turla Collaborate to Deploy Kazuar Backdoor in Ukraine

Related Posts

Microsoft 365 Admin Center Outage Blocks Access for Admins Worldwide Cyber Security News
Chinese State-Sponsored Hackers Attacking Semiconductor Industry with Weaponized Cobalt Strike Cyber Security News
Windows Docker Desktop Vulnerability Leads to Full Host Compromise Cyber Security News
New Android Malware Mimics as SBI Card, Axis Bank Apps to Steal Users Financial Data Cyber Security News
Sophos Intercept X for Windows Vulnerabilities Enable Arbitrary Code Execution Cyber Security News
Top 10 Best Security Orchestration, Automation, And Response (SOAR) Tools in 2025 Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft Warns of Hackers Abuse Teams Features and Capabilities to Deliver Malware
  • Why Threat Prioritization Is the Key SOC Performance Driver  
  • BK Technologies Data Breach – Hackers Compromise IT Systems and Exfiltrate Data
  • BatShadow Group Uses New Go-Based ‘Vampire Bot’ Malware to Hunt Job Seekers
  • Google’s New AI Doesn’t Just Find Vulnerabilities — It Rewrites Code to Patch Them

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft Warns of Hackers Abuse Teams Features and Capabilities to Deliver Malware
  • Why Threat Prioritization Is the Key SOC Performance Driver  
  • BK Technologies Data Breach – Hackers Compromise IT Systems and Exfiltrate Data
  • BatShadow Group Uses New Go-Based ‘Vampire Bot’ Malware to Hunt Job Seekers
  • Google’s New AI Doesn’t Just Find Vulnerabilities — It Rewrites Code to Patch Them

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News