Meta Verification Phishing: How a Blue Badge Lure Can Lead to Facebook Page Takeover
ID: 2a0e2d5f-4a84-5152-9fba-d0d31361cc27
STIX ID: report--2a0e2d5f-4a84-5152-9fba-d0d31361cc27
Feed Name: Blog – Hornetsecurity – Next-Gen Microsoft 365 Security
Hornetsecurity’s Threat Intelligence Lab analyzed a Meta-themed phishing campaign targeting French-speaking Facebook Page owners by luring victims with fake verification badges. The campaign abuses Google AppSheet and attacker-controlled redirectors to present a Multi-stage verification workflow that collects Page information, personal details, Facebook credentials, MFA codes, and identity documents; it stages data in encrypted browser localStorage before exfiltration, is multilingual and reusable, and includes indicators of compromise and defensive recommendations for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
