There’s A Sophisticated Phishing Attack Out There That’s Targeting Meta Business Accounts According to Fortra

While the recent Meta outages have grabbed headlines, the latest research from Fortra analysts reveals a chilling development in the cyber threat landscape: a large-scale phishing attack aimed at compromising Meta Business Accounts

The campaign incorporates several atypical tactics to carry out the attack, including expertly crafted phishing emails, deceptive live support chats, and manipulation of Google notifications and QR codes. Fortra analysts have so far detected thousands of phishing emails associated with this campaign targeting a broad range of industries.

The targeting of Meta for Business brings into focus the high value compromised businesses on social channels hold for cybercriminals. While individual accounts often bear the brunt of such attacks, the ramifications of a breach in a business context are far-reaching, with potentially devastating consequences for both reputation and financial security.

I sent some questions over to Michael Tyler, Senior Director of Security Operations for Fortra to get some more insight on this campaign. Here’s what he said:

Can you describe the campaign and who the targets are?

  • Meta Business Suite, also known as Meta for Business, is a set of tools around managing a business’ presence on the Facebook and Instagram platforms.  Access to Meta Business Suite is granted through an underlying Facebook or Instagram account.   This campaign is leveraging a sophisticated phishing attack in order to obtain access to accounts with access to Meta Business Suite.   Targets are organizations of every size.   Fortra observed and blocked thousands of threats matching this campaign targeting several dozen organizations over a period of several weeks.   In some cases, the phishing emails were sent specifically to members of the marketing team at the organization, indicating that the adversary had done research to know which employees were most likely to have the target credentials.

How novel is the attack that is used by the threat actor(s)?

  • The concept of phishing itself is nothing new.  However, this campaign had several notable points.
    • The first is the impersonation of Meta for Business, combined with the tailored recipient list noticed at some organizations.  While not novel in and of itself it indicates that the adversary launching this campaign went to at least some degree of effort to deliver a targeted attack, as opposed to a shotgun style approach typically seen in low-complexity phishing attacks.   The hypothesis that this was a tailored attack is also supported by the phishing website itself, which is the next novel point.
    • The phishing site itself was very advanced and contained several unusual features.  Chief among these was that the phish was interactive. . . upon providing your username you would be placed in a live chat with a purported member of Meta’s “Security Team”.  In reality, the phishing site was initiating a connection to a Telegram channel controlled by the adversary, who was able to communicate with the victim in real time.  Part way through the interaction, the “live chat” would freeze and the victim would be required to provide their password to “reauthenticate”, whereupon the victim would be prompted by the security team members for any MFA codes or access authorizations that may be required to gain control over the account.  This is a particularly devious social engineering technique; by delaying request for the password until after the victim is already invested in a conversation with the fake support agent, it greatly increases the chance that the victim will provide this information so that they can complete the interaction they’ve already started.

What do you believe is the end goal of the campaign?

  • It’s difficult to say exactly what the end goal of a particular campaign is.  What is clear is that Meta for business accounts have specific value to adversaries.   Fortra has observed several adversary behaviors that could be end goals of a campaign such as this.
    • The simplest is resell.  The adversary launching this campaign could simply intend to sell access to any captured accounts on the dark web.  The buyer would then use the account for their own purposes, which might include one of the below endgames.
    • An adversary might use the account to impersonate the organization.  This could take several forms, from attempting to use DMs or other on-platform features to pivot into even more valuable accounts, or using the account to post disinformation for some purpose (perhaps motivated by geopolitical, financial, or hacktivism factors).  Additionally, if your Meta Business account is based off of a Facebook account, an adversary could impersonate you on any program using the “Login with Facebook” authentication method.
    • An adversary could lock the original owner out of the account, and then attempt to ransom access to the account back to the original owner.   This tactic can be particularly effective when employed against organizations who use social media as their primary marketing channel.
    • An adversary may also attempt to use the account to post ads for counterfeit goods.  As social media companies have continued to refine their targeting algorithms, more and more goods purchases are initiated over a social media ad.  Counterfeiters have taken notice; Fortra has observed a large increase in the advertisement of counterfeit goods via social media platforms over the past several years.  By using an already verified business account, adversaries can bypass some of the social media platform’s fraud controls and have a generally higher success rate.  If the account has payment methods established, the adversary can use the victim’s funds to launch their ads as well.

What can businesses do to mitigate this attack?

  • Best practices around Email Security and end-user Security Awareness Training are paramount.  By using a multi-layered email security solution that can block malicious emails from being delivered to end users and educating end users on how to identify and report suspicious emails that evade security you greatly decrease the risk of having your credentials compromised
  • Additionally, businesses should take care to secure their Meta for business account using the most advanced identity features available to them (MFA, Security Keys, and unrecognized device alerts as of this writing).  They should also limit access to account credentials to those individuals who absolutely require them.  An even more secure implementation is to consider having different individuals control different authentication factors.  For example, have the main user of the account own the password, but a separate individual own the device which receives MFA codes.   This may not be feasible in some organizations, but forcing multiple individuals to be involved in a login attempt gives more opportunity for someone to recognize a scam.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading