Introduction
During an investigation into phishing activity targeting users across the Middle East and North Africa (MENA), Group-IB analysts identified multiple fraudulent Facebook accounts impersonating politicians, public figures, and trusted organizations. These accounts promoted fake offers, including free mobile internet packages, financial compensation, and government subsidy programs. Victims were encouraged to click embedded links to claim the advertised benefits, but were instead redirected through a chain of intermediary websites that ultimately led to phishing and traffic monetization infrastructure.
A deeper analysis of the underlying infrastructure revealed that these campaigns were not isolated incidents. By bypassing multiple layers of traffic cloaking and tracing the campaign’s telemetry, Group-IB researchers identified the centralized platform powering the…
Configure your social media privacy settings so that only “Friends” can see your contact information, birthday, or location, reducing the data available to social engineers.
