
A sophisticated global phishing operation dubbed “Meta Mirage” is actively targeting businesses using Meta’s Business Suite, security researchers at CTM360 have revealed. The campaign specifically aims to hijack high-value accounts that manage advertising and official brand pages.
## Alarming Scale and Sophisticated Tactics
Researchers have identified over 14,000 malicious URLs associated with this campaign, with nearly 78% evading browser security filters at the time of discovery. The attackers host fake pages on trusted cloud platforms including GitHub, Firebase, and Vercel, making the scams difficult to detect—a technique similar to recent Microsoft-reported attacks on Kubernetes applications.
The cybercriminals impersonate official Meta communications, sending fake alerts about policy violations, account suspensions, or verification requirements through emails and direct messages. These deceptive messages appear urgent and authoritative, mimicking legitimate Meta communications.
## Two-Pronged Attack Strategy
The attackers employ two primary methods:
1. **Credential Theft**: Victims are tricked into entering passwords and one-time passwords (OTPs) on convincing fake websites. Deliberately triggered error messages force users to re-enter credentials, ensuring accurate stolen information.
2. **Cookie Theft**: Attackers steal browser cookies to maintain access to compromised accounts even without passwords.
Compromised accounts are frequently exploited to run malicious advertising campaigns, amplifying the damage to both the affected business and its audience.
## Calculated Psychological Approach
The attackers use a structured approach, beginning with mild notifications that progressively escalate in urgency. Initial messages mention generic policy violations, while later communications threaten immediate account suspension or deletion, creating anxiety that drives hasty action without proper verification.
## Protection Recommendations
CTM360 recommends these protective measures:
– Use only official devices for business social media management
– Maintain separate business-only email addresses
– Enable Two-Factor Authentication (2FA)
– Regularly review account security settings and active sessions
– Train staff to recognize and report suspicious messages
This widespread campaign highlights the critical importance of vigilance and proactive security measures in protecting valuable online business assets.
