{"id":18878,"date":"2022-04-28T07:10:05","date_gmt":"2022-04-28T15:10:05","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2022\/04\/28\/news-12611\/"},"modified":"2022-04-28T07:10:05","modified_gmt":"2022-04-28T15:10:05","slug":"news-12611","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2022\/04\/28\/news-12611\/","title":{"rendered":"Facebook phishers threaten users with Page Recovery Help Support"},"content":{"rendered":"<p><strong>Credit to Author: Christopher Boyd| Date: Thu, 28 Apr 2022 14:11:47 +0000<\/strong><\/p>\n<p>We\u2019ve seen multiple hijacked profiles on Facebook recently claiming to be account recovery services. These bogus account recovery services aren&#8217;t here to help. They&#8217;re actually just trying to scare users into falling for phishing attempts.<\/p>\n<p>The people behind these scams target Facebook pages belonging to musicians, products, and businesses of all kinds. In what may be a peculiar coincidence, quite a few of the accounts we looked at belonged to spa\/beauty treatment small businesses.<\/p>\n<p>Once the page has been taken over, the hijacker changes the name, profile picture, and more to look like it&#8217;s a support page.<\/p>\n<p>Here\u2019s a typical list of some of these compromised accounts:<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" data-attachment-id=\"55892\" data-permalink=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/04\/facebook-phishers-threaten-users-with-page-recovery-help-support\/attachment\/created-with-gimp-17\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/fbcheck6.jpg\" data-orig-size=\"648,978\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;Created with GIMP&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;Created with GIMP&quot;,&quot;orientation&quot;:&quot;1&quot;}\" data-image-title=\"Created with GIMP\" data-image-description=\"\" data-image-caption=\"&lt;p&gt;Created with GIMP&lt;\/p&gt; \" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/fbcheck6-199x300.jpg\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/fbcheck6-398x600.jpg\" loading=\"lazy\" width=\"398\" height=\"600\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/fbcheck6-398x600.jpg\" alt=\"\" class=\"wp-image-55892\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/fbcheck6-398x600.jpg 398w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/fbcheck6-199x300.jpg 199w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/fbcheck6.jpg 648w\" sizes=\"auto, (max-width: 398px) 100vw, 398px\" \/><figcaption><em>That&#8217;s a lot of support<\/em><\/figcaption><\/figure>\n<\/div>\n<p>As you can see, there&#8217;s no real rhyme or reason to the hijacks. Just a big list of random pages ready to get up to mischief.<\/p>\n<h2>With great power comes great transparency<\/h2>\n<p>The dates of the pages being altered can be seen via Facebook\u2019s \u201cPage transparency\u201d popup. The majority of those we&#8217;ve observed appear to have been hijacked in the last month or so. If you&#8217;re not familiar with this popup, it&#8217;s all about <a href=\"https:\/\/www.facebook.com\/help\/323314944866264\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">providing a fuller picture<\/a> of what a page is all about.<\/p>\n<p>When was it created? How many times has the name changed? Has it merged with another page? Which country does it operate out of? This is what the transparency box looks like:<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" data-attachment-id=\"55893\" data-permalink=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/04\/facebook-phishers-threaten-users-with-page-recovery-help-support\/attachment\/created-with-gimp-18\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/fbcheck3.jpg\" data-orig-size=\"522,606\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;Created with GIMP&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;Created with GIMP&quot;,&quot;orientation&quot;:&quot;1&quot;}\" data-image-title=\"Created with GIMP\" data-image-description=\"\" data-image-caption=\"&lt;p&gt;Created with GIMP&lt;\/p&gt; \" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/fbcheck3-258x300.jpg\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/fbcheck3-517x600.jpg\" loading=\"lazy\" width=\"517\" height=\"600\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/fbcheck3-517x600.jpg\" alt=\"\" class=\"wp-image-55893\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/fbcheck3-517x600.jpg 517w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/fbcheck3-258x300.jpg 258w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/fbcheck3.jpg 522w\" sizes=\"auto, (max-width: 517px) 100vw, 517px\" \/><figcaption><em>Transparency report<\/em><\/figcaption><\/figure>\n<\/div>\n<h2>How do scammers go phishing?<\/h2>\n<p>Businesses on Facebook have a dedicated page for their organisation, containing information, updates, and posts about the latest happenings. These pages are operated by one or more Admins, <a href=\"https:\/\/blog.hootsuite.com\/steps-to-create-a-facebook-business-page\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">using their personal accounts<\/a>. Should any of those users suffer an account compromise, the business page may become vulnerable as a result. The compromiser is able to set about changing the business page to suit their needs.<\/p>\n<p>Let&#8217;s assume an account responsible for a page has just been compromised. The people behind this have made significant alterations to the page description and layout. Instead of a portal advertising the latest gardening tools or hair fashion, it&#8217;s now claiming to help you recover lost Facebook pages.<\/p>\n<p>Potential victims are linked to a notification on the compromised account\u2019s page via messaging. These pages are also easy to stumble upon while searching for content in Facebook itself &#8211; this is how a relative first brought it to my attention. A rather dire warning lies in wait for anyone viewing it:<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" data-attachment-id=\"55896\" data-permalink=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/04\/facebook-phishers-threaten-users-with-page-recovery-help-support\/attachment\/created-with-gimp-20\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/fbcheck4.jpg\" data-orig-size=\"885,818\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;Created with GIMP&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;Created with GIMP&quot;,&quot;orientation&quot;:&quot;1&quot;}\" data-image-title=\"Created with GIMP\" data-image-description=\"\" data-image-caption=\"&lt;p&gt;Created with GIMP&lt;\/p&gt; \" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/fbcheck4-300x277.jpg\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/fbcheck4-600x555.jpg\" loading=\"lazy\" width=\"600\" height=\"555\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/fbcheck4-600x555.jpg\" alt=\"\" class=\"wp-image-55896\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/fbcheck4-600x555.jpg 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/fbcheck4-300x277.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/fbcheck4.jpg 885w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><figcaption><em>It&#8217;s account blocking time<\/em><\/figcaption><\/figure>\n<\/div>\n<blockquote class=\"wp-block-quote\">\n<p><em>Your account will be deactivated. This is because someone has reported you with non-compliance with the terms of service. If you are the original owner of this account, re-verify your account to avoid blocking. Click here [URL removed]<\/em><\/p>\n<p><em>If you do not confirm within 12 hours, our system will automatically block your account and you will not be able to use it.<\/em><\/p>\n<p><em>Thanks,<\/em><\/p>\n<p><em>Bruce,<\/em><\/p>\n<p><em>Security Support Specialist<\/em><\/p>\n<\/blockquote>\n<p>Well, that\u2019s alarming. Thanks, Bruce, if it <em>is<\/em> your real name (it is not). Here&#8221;s another example of a compromised page:<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" data-attachment-id=\"55898\" data-permalink=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/04\/facebook-phishers-threaten-users-with-page-recovery-help-support\/attachment\/created-with-gimp-21\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/fbcheck5-1.jpg\" data-orig-size=\"915,916\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;Created with GIMP&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;Created with GIMP&quot;,&quot;orientation&quot;:&quot;1&quot;}\" data-image-title=\"Created with GIMP\" data-image-description=\"\" data-image-caption=\"&lt;p&gt;Created with GIMP&lt;\/p&gt; \" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/fbcheck5-1-300x300.jpg\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/fbcheck5-1-600x600.jpg\" loading=\"lazy\" width=\"600\" height=\"600\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/fbcheck5-1-600x600.jpg\" alt=\"\" class=\"wp-image-55898\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/fbcheck5-1-600x600.jpg 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/fbcheck5-1-300x300.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/fbcheck5-1-150x150.jpg 150w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/fbcheck5-1.jpg 915w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><figcaption><em>Searching for hits<\/em><\/figcaption><\/figure>\n<\/div>\n<p>Note the attempt at some form of keyword\/search spam at the bottom, in an effort to be as visible to users as possible.<\/p>\n<h2>Landing on the phish<\/h2>\n<p>No matter which compromised warning page you land on, they all want you to visit a phishing page. These differ from account to account, but the landing pages are all pretty much the same. Here\u2019s one example:<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" data-attachment-id=\"55899\" data-permalink=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/04\/facebook-phishers-threaten-users-with-page-recovery-help-support\/attachment\/created-with-gimp-22\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/fbcheck1.jpg\" data-orig-size=\"849,595\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;Created with GIMP&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;Created with GIMP&quot;,&quot;orientation&quot;:&quot;1&quot;}\" data-image-title=\"Created with GIMP\" data-image-description=\"\" data-image-caption=\"&lt;p&gt;Created with GIMP&lt;\/p&gt; \" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/fbcheck1-300x210.jpg\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/fbcheck1-600x420.jpg\" loading=\"lazy\" width=\"600\" height=\"420\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/fbcheck1-600x420.jpg\" alt=\"\" class=\"wp-image-55899\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/fbcheck1-600x420.jpg 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/fbcheck1-300x210.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/fbcheck1.jpg 849w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><figcaption><em>Phishy behaviour<\/em><\/figcaption><\/figure>\n<\/div>\n<p>Note that the page here isn\u2019t even HTTPs.<\/p>\n<p>We can\u2019t say for sure what they\u2019re doing with the stolen accounts, but once they have them, spam and malicious messaging would be the best bet. They&#8217;ll likely be used to compromise more accounts down the line. If any stolen accounts have access to business pages, no doubt they&#8217;ll create more fake recovery pages too. Whatever they&#8217;re up to, it won&#8217;t be anything good.<\/p>\n<p>While drafting this blog, we became aware of research already published by <a href=\"https:\/\/abnormalsecurity.com\/blog\/facebook-domain-credential-phishing-attack\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Abnormal Security<\/a>. The research covers similar tactics: hijacking business pages to phish. The fraudulent activity covered there includes fake emails, and a longer time limit (48 hours to respond, instead of just 12), and its well worth reading.<\/p>\n<h2>Keeping your Facebook account safe<\/h2>\n<ul>\n<li>Enable <a href=\"https:\/\/en-gb.facebook.com\/help\/148233965247823\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">two-factor authentication on your account<\/a>.<\/li>\n<li>Consider using a password manager. It will help you use a different and difficult password for every online account you have. Better still, if the password manager has the ability to match the page you&#8217;re on with the one you&#8217;re trying to log into, it won&#8217;t work if the site is a phish.<\/li>\n<li>Set up <a href=\"https:\/\/www.facebook.com\/help\/162968940433354?helpref=faq_content\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">login alerts<\/a> so you get notified if anyone tries to login to your account from a new device.<\/li>\n<li>Don&#8217;t believe random warnings of account loss. You can always reach out to contact Facebook support directly if you&#8217;re unsure.<\/li>\n<li>If you need to report that your own account has been compromised, you can <a href=\"https:\/\/en-gb.facebook.com\/hacked\" target=\"_blank\" rel=\"noreferrer noopener\">send Facebook a message directly about your problem.<\/a> Facebook also provides a variety of information related to specific situations <a href=\"https:\/\/en-gb.facebook.com\/help\/738660629556925\" target=\"_blank\" rel=\"noreferrer noopener\">here<\/a>.<\/li>\n<\/ul>\n<p>Pressuring people into handing over logins &#8220;or else&#8221; is a pressure tactic that&#8217;s been around forever. Making them &#8220;confirm&#8221; in 12 hours or less  is one of the tighter time limits we&#8217;ve seen. Don&#8217;t panic, contact support, and go about your day. Those dire warnings of account loss and removal are almost certainly going to be a lot of phishy nonsense.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/04\/facebook-phishers-threaten-users-with-page-recovery-help-support\/\">Facebook phishers threaten users with Page Recovery Help Support<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/04\/facebook-phishers-threaten-users-with-page-recovery-help-support\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Christopher Boyd| Date: Thu, 28 Apr 2022 14:11:47 +0000<\/strong><\/p>\n<p>We take a look at a wave of compromised facebook pages claiming your account is going to be closed in 12 hours.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/04\/facebook-phishers-threaten-users-with-page-recovery-help-support\/\">Facebook phishers threaten users with Page Recovery Help Support<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[25853,3589,3924,5340,10574],"class_list":["post-18878","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-compromised","tag-facebook","tag-phishing","tag-recovery","tag-scams"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18878","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=18878"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18878\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=18878"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=18878"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=18878"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}