Massive Facebook Phishing Operation Leverages AppSheet, Netlify, and Telegram
ID: d7f970eb-2ef8-5496-8213-6dcdaa831c58
STIX ID: report--d7f970eb-2ef8-5496-8213-6dcdaa831c58
Feed Name: GBHackers
Guardio Labs uncovered 'AccountDumpling', a sophisticated phishing campaign that compromised ~30,000 Facebook accounts by abusing Google AppSheet to send fully authenticated phishing emails that bypass SPF/DKIM/DMARC; attackers used multi-cluster infrastructure (Netlify, Vercel, Google Drive) to host bespoke phishing pages, real-time Socket.IO panels to capture MFA and session data, and Telegram bots to exfiltrate and monetize stolen account access, with links to Vietnamese operators discovered in document metadata and source comments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
