Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Fake Facebook Offers Exploit Users in MENA Region

Fake Facebook Offers Exploit Users in MENA Region

Posted on June 15, 2026 By CWS

Cybersecurity experts have uncovered a new scam targeting individuals across the Middle East and North Africa. The scam employs fraudulent Facebook accounts that mimic well-known politicians, public figures, and reputable organizations to deceive users.

Deceptive Online Offers

These accounts promote enticing but fake offers, such as free mobile internet, financial aid, and government subsidies. Unsuspecting victims are lured to click on embedded links, supposedly to claim these benefits, but are instead redirected to a series of intermediary websites leading to phishing sites and traffic monetization schemes.

According to analysts Anna Yurtaeva and Viacheslav Shevchenko from Group-IB, a Singapore-based cybersecurity company, the campaigns are linked to Sniper Dz, a phishing-as-a-service platform dismantled recently in an operation led by INTERPOL. This platform not only facilitates credential theft but also generates illegal revenue through browser notifications, premium SMS subscriptions, and investment scams.

Complex Scam Structure

The typical victim journey begins with local social engineering tactics. Scammers impersonate telecom companies like Algérie Télécom to promote fake offers, directing users to domains hosted on link aggregation platforms such as Linkbio and Linktree. These platforms serve as a bridge between social media posts and the scam’s final destination.

Victims are eventually led to a page that requests browser notification permissions, asking users to click “Allow” to continue. Behind the scenes, this action subscribes the browser to a push notification system using a shared VAPID public key, a method seen in various scams masquerading as telecom and investment offers in different regions.

Advanced Manipulation Techniques

Additionally, the scam employs techniques to trap users, such as back button hijacking, which creates fake history states to prevent users from leaving the scam environment. This technique increases ad impressions and promotes unsolicited content.

The scam also uses a tab-under technique, where clicking a link opens a new tab, and a delayed script redirects the original tab to a scam-controlled site. This ensures the scam continues to operate even when victims think they have exited the site.

Once users are integrated into the notification system, they are directed through a traffic distribution system that selects scams based on device type, location, and mobile carrier. These scams include premium-rate calls, SMS fraud, and investment schemes.

Significance and Future Outlook

This campaign highlights the evolution of fraud tactics, which now exploit legitimate web technologies instead of traditional malware. By leveraging trusted platforms and browser features, scammers effectively guide victims through an intricate monetization process.

As online scams become increasingly sophisticated, it is crucial for users to remain vigilant and for authorities to continue dismantling these networks. Understanding these methods is vital for enhancing cybersecurity measures and protecting users globally.

The Hacker News Tags:ad fraud, browser notifications, Cybersecurity, Facebook scams, INTERPOL operation, MENA, online security, Phishing, Sniper Dz, social engineering

Post navigation

Previous Post: AI SPERA Presents AITEM at Infosecurity Europe 2026
Next Post: Active Exploitation of PAN-OS VPN Vulnerability Alert

Related Posts

FROST Attack Exploits SSD Timing to Track Website Visits FROST Attack Exploits SSD Timing to Track Website Visits The Hacker News
Researchers Warn RondoDox Botnet is Weaponizing Over 50 Flaws Across 30+ Vendors Researchers Warn RondoDox Botnet is Weaponizing Over 50 Flaws Across 30+ Vendors The Hacker News
CISA Warns of Active n8n Vulnerability Exploitation CISA Warns of Active n8n Vulnerability Exploitation The Hacker News
PoisonSeed Hackers Bypass FIDO Keys Using QR Phishing and Cross-Device Sign-In Abuse PoisonSeed Hackers Bypass FIDO Keys Using QR Phishing and Cross-Device Sign-In Abuse The Hacker News
Bitfinex Hack Convict Ilya Lichtenstein Released Early Under U.S. First Step Act Bitfinex Hack Convict Ilya Lichtenstein Released Early Under U.S. First Step Act The Hacker News
Critical Dahua Camera Flaws Enable Remote Hijack via ONVIF and File Upload Exploits Critical Dahua Camera Flaws Enable Remote Hijack via ONVIF and File Upload Exploits The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Veeam Agent Vulnerability Exploited for SYSTEM Privileges
  • Critical AI Gateway Flaw Exposes Bifrost to Command Attacks
  • PowerShell Exploited in New TASK#STOMP Cyber Intrusion
  • Malicious npm Package Targets Twilio Developers
  • Enhancing SOC Efficiency with Threat Intelligence

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Veeam Agent Vulnerability Exploited for SYSTEM Privileges
  • Critical AI Gateway Flaw Exposes Bifrost to Command Attacks
  • PowerShell Exploited in New TASK#STOMP Cyber Intrusion
  • Malicious npm Package Targets Twilio Developers
  • Enhancing SOC Efficiency with Threat Intelligence

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark