logo

ClickFix Facebook Session Hijacking Campaign Targets Creators at Scale

ID: f47a816d-b009-5a92-aef8-22134a3a4334

STIX ID: report--f47a816d-b009-5a92-aef8-22134a3a4334

Feed Name: Hunt.io Blog

Threat Score
75/100

Date Published: 2026-02-16

Date Updated: 2026-04-28

...
...

This report details the ClickFix phishing campaign that tricks Facebook creators and business pages into handing over live session cookies (c_user and xs) via multi-stage fake verification and appeal pages; attackers then exfiltrate tokens and, if needed, backup codes and passwords using third-party serverless form backends. The analysis enumerates ~115 pages, 103 hostnames, multiple exfiltration endpoints (submit-form.com, Formspark, shiper.app), title- and template-based pivots, operational guidance for defenders, and mapped MITRE ATT&CK techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.