Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

New Phishing Attack Targets Facebook Users to Steal Login Credentials

Posted on September 19, 2025September 19, 2025 By CWS

A classy phishing marketing campaign has lately emerged, focusing on Fb customers with rigorously crafted emails designed to reap login credentials.

Attackers leverage the platform’s personal exterior URL warning system to cloak malicious hyperlinks, presenting URLs that seem reliable whereas redirecting victims to counterfeit Fb login pages.

The preliminary lure arrives as an pressing safety notification, warning customers of “unauthorized entry makes an attempt” or prompting them to confirm account exercise.

The e-mail’s design carefully mirrors Fb’s styling, full with social media icons and footer disclaimers, creating a way of authenticity and main recipients to click on with out hesitation.

Phishing (Supply – X)

The marketing campaign’s attain spans a number of languages, together with English, German, Spanish, and Korean, broadening its potential sufferer pool.

Phishing URLs constantly comply with a sample of benign domains forwarded by means of Fb’s redirector service (e.g., httpst.co/MS24b2xu6p), which then reroute to attackers’ infrastructure.

SpiderLabs analysts recognized this system after inspecting dozens of electronic mail samples, noting how the redirect mechanism each evades hyperlink scanners and bypasses consumer suspicion.

Victims who comply with the hyperlink encounter a near-perfect reproduction of Fb’s login interface, the place credentials submitted are instantly exfiltrated to a command-and-control server.

On profitable submission, the faux portal executes a short JavaScript snippet to show an “Incorrect password” error, prompting customers to re-enter their particulars—unwittingly supplying attackers with legitimate credentials on the second try.

The harvested information consists of electronic mail addresses, telephone numbers, and passwords, that are saved in a PHP backend script for later retrieval by risk actors.

Redirect-Primarily based An infection Mechanism

The core innovation of this phishing marketing campaign lies in its abuse of Fb’s exterior URL warning system as an an infection mechanism.

Moderately than linking on to malicious domains, attackers assemble a URL of the shape:-

Confirm Your Account

This hyperlink leverages Fb’s l.fb.com redirect service, embedding the precise phishing web site within the u= parameter.

When clicked, Fb presents a warning banner however finally forwards the sufferer to the malicious web page, lending credibility to the vacation spot.

As soon as on the phishing web site, the HTML type collects credentials by way of:-

Upon submission, a JavaScript routine triggers a second redirect again to Fb, displaying an error discover to the consumer and minimizing suspicion.

This redirect-based an infection mechanism not solely bypasses electronic mail safety gateways but additionally exploits consumer belief in Fb’s area, making detection and prevention considerably tougher.

Discover this Story Fascinating! Observe us on Google Information, LinkedIn, and X to Get Extra Immediate Updates.

Cyber Security News Tags:Attack, Credentials, Facebook, Login, Phishing, Steal, Targets, Users

Post navigation

Previous Post: Unpatched Vulnerabilities Expose Novakon HMIs to Remote Hacking
Next Post: Russian Hackers Gamaredon and Turla Collaborate to Deploy Kazuar Backdoor in Ukraine

Related Posts

Hackers Abuse VPS Servers To Compromise Software-as-a-service (SaaS) Accounts Cyber Security News
Multiple Splunk Enterprise Vulnerabilities Let Attackers Execute Unauthorized JavaScript code Cyber Security News
INE Earns Multiple G2 Winter 2026 Badges Across Global Markets Cyber Security News
UAC-0099 Hackers Weaponizing HTA Files to Deliver MATCHBOIL Loader Malware Cyber Security News
Lucid PhaaS With 17,500 Phishing Domains Mimics 316 Brands From 74 Countries Cyber Security News
Malicious Python Package Mimic as Attacking Discord Developers With Malicious Remote Commands Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Expose All User Records from Popular Dark Web Forum
  • China-Linked Hackers Exploit VMware ESXi Zero-Days to Escape Virtual Machines
  • xRAT Malware Attacking Windows Users Disguised as Adult Game
  • Fog Ransomware Attacking US Organizations Leveraging Compromised VPN Credentials
  • In Other News: 8,000 Ransomware Attacks, China Hacked US Gov Emails, IDHS Breach Impacts 700k

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Expose All User Records from Popular Dark Web Forum
  • China-Linked Hackers Exploit VMware ESXi Zero-Days to Escape Virtual Machines
  • xRAT Malware Attacking Windows Users Disguised as Adult Game
  • Fog Ransomware Attacking US Organizations Leveraging Compromised VPN Credentials
  • In Other News: 8,000 Ransomware Attacks, China Hacked US Gov Emails, IDHS Breach Impacts 700k

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark