logo

Massive Facebook Phishing Operation Leverages AppSheet, Netlify, and Telegram

ID: d7f970eb-2ef8-5496-8213-6dcdaa831c58

STIX ID: report--d7f970eb-2ef8-5496-8213-6dcdaa831c58

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-05-02

Date Updated: 2026-05-02

Author: Divya

...
...

Guardio Labs uncovered 'AccountDumpling', a sophisticated phishing campaign that compromised ~30,000 Facebook accounts by abusing Google AppSheet to send fully authenticated phishing emails that bypass SPF/DKIM/DMARC; attackers used multi-cluster infrastructure (Netlify, Vercel, Google Drive) to host bespoke phishing pages, real-time Socket.IO panels to capture MFA and session data, and Telegram bots to exfiltrate and monetize stolen account access, with links to Vietnamese operators discovered in document metadata and source comments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.