Attackers Weaponize Real Meta Business Manager Notifications In New Phishing Campaign

Cybercriminals are constantly looking for ways to bypass email security filters, and their latest method involves using legitimate platforms against their own users.

A newly discovered phishing campaign is abusing real Meta Business Manager partner request notifications to trick business owners and page administrators.

Because these emails are sent directly from Meta’s official, trusted infrastructure, they easily slip past traditional spam filters and land in the victim’s primary inbox.

The Mechanics Of The Attack

The core of this attack relies on a feature within Meta Business Manager that allows businesses to send partner requests to other accounts.

Threat actors are exploiting this legitimate tool by manipulating their own account names.

Instead of using a normal business name, the attackers change their account name to display a deceptive message, such as a warning about page suspension or copyright violations.

They also embed malicious phishing links directly into these fake account names or request details.

When the target receives the partner request email, it looks highly authentic because it actually originates from Facebook’s real servers.

Security researchers at MailMarshal recently detected this sophisticated campaign in the wild. If a user clicks the embedded link in the notification, they are not taken to a real Facebook page.

Instead, they are redirected to carefully crafted fake Facebook Help landing pages designed to look exactly like the real Meta support center.

Meta Notifications Abused (Source: Spider Labs)
Meta Notifications Abused (Source: Spider Labs)

Indicators Of Compromise and Protection

Recognizing the infrastructure used by these attackers is crucial for blocking the threat and protecting corporate assets.

Cybersecurity teams and network administrators should update their blocklists to prevent users from accessing the malicious domains associated with this campaign.

The identified Indicators of Compromise (IOCs) include several deceptive URLs designed to mimic official support channels.

Known malicious domains to block:

  • aisupportpage[.]online
  • helpforpage[.]online
  • pagereport[.]online
  • pagereview[.]online
  • pagesactnow[.]help
  • pageshub[.]click

According to Spider Labs research, to protect your organization from this type of abuse, users must remain highly skeptical of urgent notifications, even if they come from a trusted sender like Meta.

Always log in directly to your Meta Business Manager account in your web browser to check for alerts, rather than clicking on links in an email. Review any partner requests carefully and deny those from unknown or suspicious sources.

Furthermore, ensure that your team is trained to spot fake login pages by always verifying the URL in the browser’s address bar.

Implementing hardware-based security keys for two-factor authentication can also stop attackers from accessing your account, even if they manage to steal your password through a fake portal.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories