• About
  • Advertise
  • Privacy & Policy
  • Contact
Wednesday, July 22, 2026
TheClevelandAmerican
  • Home
  • U.S.
  • World
  • Business
  • Science
  • Tech
  • Sport
  • Entertainment
  • Contact Us
No Result
View All Result
  • Home
  • U.S.
  • World
  • Business
  • Science
  • Tech
  • Sport
  • Entertainment
  • Contact Us
No Result
View All Result
TheClevelandAmerican
No Result
View All Result
Home Tech

“Cyber ​​criminals use massive ‘phishing’ campaign to send accounts through Messenger” | Daily list

Misty Tate by Misty Tate
September 13, 2023
“Cyber ​​criminals use massive ‘phishing’ campaign to send accounts through Messenger” |  Daily list
Share on FacebookShare on Twitter

Cybercriminals have launched a large-scale campaign in the past month against Facebook business accounts using the Messenger platform, where they send messages. Violation of service policies and links to infected compressed files This includes ‘cookies’ and ‘scripts’ that can retrieve passwords.

The Vietnam-based attack group was able to compromise thousands of companies and organizations through the Facebook messaging service using a ‘phishing’ technique, Cardio Labs has confirmed. It mainly targets the last 30 days. North America, Europe and Oceania.

These cyber security experts say the attack flow is “a combination of techniques, abuse of open and free platforms, as well as Multiple blurring and occlusion modes“, according to their statement describing its operation.

To carry out these campaigns, cybercriminals send a message with a ‘url’ to corporate accounts and business owners through Messenger. These links encourage them to click on a malicious link.

Although the contents of these messages differ from cardio labs, “Everyone seems to be sharing the same environment” And these relate to product-related questions advertised on a business account or complaints posted on a page that allegedly violates the site’s policies.

Variations in code

To avoid being noticed, cybercriminals send each message in both text and subject, with different filenames, adding Unicode characters to some words, with a series of variations. This way, they avoid being detected by ‘anti-spam’ solutions.

The malicious payload (project.py) is recorded in RAR or ZIP formats, with a single file inside. One of the ‘scripts’ found by Cardio Labs showed a block structure, that is, they are executed by line. It acted as a ‘dropper’, a type of ‘malware’ that contained an executable file.

See also  An asteroid the size of the Giza pyramids has scientists worried

That way, the first file downloads another ZIP file, usually hosted on free source sites like GitHub or GitLab. The latter consists of another batch script that runs directly and has a specific encoding.

Specifically, the text file is encoded in UTF-16LE at the beginning and end, while most characters are in ASCII encoding. According to the researchers, this is a “clever tactic to hide the volume content” from automated scanners, preventing the attack scope from being limited.

Therefore, since it is a batch script, all lines of code are executed both benign and malignant, Python uses the environment to collect ‘cookies’ and login data, names and passwords stored in victims’ browsers.

Once the information is recorded, these communications are sent together to a Telegram or Discord channel using the application programming interface (API) of the platforms’ ‘bot’.

Besides stealing them, the malicious script deletes all cookies, resulting in victims being kicked out of their accounts. During that time, cybercriminals hijack your logins and change passwords.

The Cyber ​​Security Institute pointed out that cybercriminals have a list of “bots” and fake accounts, as well as a list of millions of accounts and pages managed by companies. 100,000 phishing messages per week worldwide.

Also, according to their statistics, of all corporate accounts on Facebook, at least 7 percent received this infected communication in the last 30 days and 0.4 percent of them downloaded the attached malicious file, so one in 250 accounts was eventually infected.

Guardio Cybersecurity researcher Oleg Zaytsev also points out that the success rate of this campaign is one in every 70 infected accounts, for credentials and account theft, users still need to run the downloaded file.

See also  China has complained to the UN about the risk of Elon Musk's satellites colliding
Misty Tate

Misty Tate

Oscar Wilde writes for The Cleveland American, covering news, politics, business, technology, sport, entertainment, and lifestyle. He focuses on clear, reliable reporting and useful information, helping readers stay informed about current events, important developments, and stories that matter.

Next Post
Luis Palma admits why he celebrated like Carlos Pavon and reveals the advice he got from David Suazo: “I was a bit restless”

Luis Palma admits why he celebrated like Carlos Pavon and reveals the advice he got from David Suazo: "I was a bit restless"

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Trending.

The song NASA banned from space – Rock & Pop

The song NASA banned from space – Rock & Pop

September 2, 2023
How To Enable Dark Mode In Google Search

How To Enable Dark Mode In Google Search

September 14, 2021
BraveWords Records Signs Colin Peterik Ahead of New Album Release

BraveWords Records Signs Colin Peterik Ahead of New Album Release

June 23, 2026
Texas Officials Call for Data Center Moratorium as Industry Convention Opens in Austin

Texas Officials Call for Data Center Moratorium as Industry Convention Opens in Austin

July 14, 2026
The phrase about the origins of Argentina, Brazilians and Mexicans is critical of President Alberto Fernandez.  International |  News

The phrase about the origins of Argentina, Brazilians and Mexicans is critical of President Alberto Fernandez. International | News

June 11, 2021
TheClevelandAmerican

We bring you high-quality content covering news, stories, and insights that matter. Explore our platform for the latest updates

Categories

  • Art
  • Business
  • Economy
  • Energy
  • Entertainment
  • Games
  • Health
  • Science
  • Sport
  • Tech
  • Top News
  • World

Recent News

Expert Shares Summer Sleep Strategies to Help Parents Maintain Healthy Bedtime Routines for Children

Expert Shares Summer Sleep Strategies to Help Parents Maintain Healthy Bedtime Routines for Children

July 21, 2026
Oklahoma Housing Finance Agency Approves Funding to Expand Affordable Housing Across the State

Oklahoma Housing Finance Agency Approves Funding to Expand Affordable Housing Across the State

July 21, 2026
  • About Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Editorial Policy

© 2026 The Cleveland American Media Portal — Independent News & Media Network.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Review
  • Security

© 2026 The Cleveland American Media Portal — Independent News & Media Network.