Behold, the Facebook phishing scam that could dupe even vigilant users

Phishers are deploying what appears to be a clever new trick to snag peoples Facebook passwords by presenting convincing replicas of single sign-on login windows on malicious sites, researchers said this week.

Websites that dont want to bother creating and securing password-based authentication systems need only access an easy-to-use programming interface. Security and cryptographic mechanisms under the hood allow the login to happen without the third-party site ever seeing the username and password.

EnlargeOne of the ingredients that made the login window look so real is that it almost perfectly reproduced what users would see if they were encountering a genuine Facebook SSO, such as the one to the right of this text.

Genuine SSOs from Facebook and Google can be dragged outside of the window of the third-party site without any part of the login prompt disappearing.

More advanced users almost certainly could have spotted the forgery by viewing the source code of the site they were visiting, too.

A password phished from a Facebook account that used MFA protection would have been of little use to attackers since they wouldnt have had the physical key or smartphone thats required when logging in from a computer that has never accessed the account before.

Original article
Author: Dangoodin001

Serving the Technologist for more than a decade. IT news, reviews, and analysis.

Dangoodin001 has recently written 7 articles on similar topics including :
  1. "Facebook removes pages following discovery of a campaign that hid in plain sight". (July 2, 2019)
  2. "The Facebook-owned messenger with 2 billion users revamps its privacy policy". (January 6, 2021)
  3. "Apps improperly obtained user data, installed malware, and committed other offenses". (September 21, 2019)
  4. "Already under scrutiny for spreading hate, social network also helps peddle spam and fraud". (April 5, 2019)
  5. "Here we go again. DOJ renews its "going dark" warning amid Facebook privacy shift". (October 4, 2019)
  6. "Group is known for its robust, custom-made malware. IT firm says the link is a mistake". (December 11, 2020)
  7. "Deletions come after allegations NSO exploit targeted 1,400 WhatsApp users". (October 30, 2019)
Posted on  ,