{"id":10055,"date":"2025-08-07T09:53:17","date_gmt":"2025-08-07T09:53:17","guid":{"rendered":"http:\/\/localhost\/?p=10055"},"modified":"2025-08-07T09:53:17","modified_gmt":"2025-08-07T09:53:17","slug":"facebook-users-targeted-in-8216login8217-phish","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=10055","title":{"rendered":"Facebook users targeted in &#8216;login&#8217; phish_MALWAREBYTES:3A37EE617EDA6A0E95059E2E8A3B71E5"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2025-08-07T14:12:45&#8243;,&#8221;description&#8221;:&#8221;A few weeks ago we warned our readers of a phishing campaign targeting Instagram users that didn\u2019t resort to the usual links to phishing websites, but used mailto: links instead. Now, it seems that these scammers have turned their attention to Facebook users.\\n\\nIt works like this: The target receives an email saying that your Facebook account was logged into from a new device. Even though the subject line says \u201cWe&#8217;ve Received a request to Reset your password for Facebook Account !\u201d\\n\\n![email header](https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2025\/08\/email_header.png) ![new device login](https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2025\/08\/email.png)\\n\\n\\u003e \u201cA user just logged into your Facebook account from a new device iPhone 14 PRO Max. We are sending you this email to verify it&#8217;s really you.\u201d\\n\\nAll the links you see in the email: \u201cReport the user\u201d, \u201cYes, me\u201d, \u201cunsubscribe\u201d, and even the obfuscated email address at the bottom, do exactly the same thing.\\n\\nThey open your default email program with a pre-addressed message with a subject line that matches the button\/text you clicked on.\\n\\nThe email addresses these messages will be sent to are the same as the ones we saw with the Instagram phish:\\n\\n  * `prestige@vacasa[.]uk.com` (typosquat of vacasa.com vacation rentals)\\n  * `ministry@syntec[.]uk.com` (typosquat of syntechnologies.co.uk hardware provider)\\n  * `technique@pdftools[.]com.de` (typosquat of pdf-tools.com software provider)\\n  * `service@boss[.]eu.com` (several possibilities)\\n  * `threaten@famy[.]in.net` (science news site, possibly compromised)\\n  * `difficulty@blackdiamond[.]com.se` (known malicious domain)\\n  * `anticipation@salomonshoes[.]us.com` (typosquat of salomon.com running shoes)\\n\\n\\n\\nThis is kind of surprising since we found last time that several of the addresses were unresponsive.\\n\\n![undeliverable](https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2025\/08\/undeliverable.png?w=1024)\\n\\nThe unusual Top-Level Domains (TLDs) like uk.com, com.de, eu.com, com.se, and us.com are actually second-level domain extensions operated by private entities, not official country-code top-level domains.\\n\\nThough these domain extensions themselves are legitimate registration services, their openness and global accessibility mean they can be misused by phishers and other cybercriminals to make them look more legitimate or country-specific than generic .com domains. They may also be used to typosquat legitimate domains.\\n\\n## How to avoid Facebook phishing\\n\\nSince we can expect to see more phishing campaigns that use mailto: links, here are some tips to avoid falling victim to such a scam.\\n\\n  * As with regular links, scrutinize the destination of an email link. Even if the domain looks legitimate, your Facebook account isn\u2019t secured by a shoe maker or vacation provider, or someone using a gmail address. The email address should be one that belongs to Facebook or Meta.\\n  * Remember that legitimate companies will not ask you to mail them your account details, credentials, or other sensitive information.\\n  * If there\u2019s an urgency to respond to an email, take a pause before you do. This is a classic scammer trick to get you to act before you can think.\\n  * Don\u2019t reply if the warning looks suspicious in any way. Sending an email will tell the phishers that your email address is active, and it will be targeted even more.\\n  * Do an online search about the email you received, in case others are posting about similar scams.\\n  * Use Malwarebytes Scam Guard to assess the message. It will tell you whether it\u2019s a scam or give you tips how you can find out if it isn\u2019t sure.\\n\\n\\n\\n**We don &#8216;t just report on threats &#8211; we help protect your social media**\\n\\nCybersecurity risks should never spread beyond a headline. Protect your social media accounts by using Malwarebytes Identity Theft Protection.&#8221;,&#8221;published&#8221;:&#8221;2025-08-07T12:31:34&#8243;,&#8221;modified&#8221;:&#8221;2025-08-07T12:31:34&#8243;,&#8221;type&#8221;:&#8221;malwarebytes&#8221;,&#8221;title&#8221;:&#8221;Facebook users targeted in \\u0026#8216;login\\u0026#8217; phish&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;MALWAREBYTES:3A37EE617EDA6A0E95059E2E8A3B71E5&#8243;,&#8221;bulletinFamily&#8221;:&#8221;blog&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[],&#8221;sourceData&#8221;:&#8221;&#8221;,&#8221;sourceHref&#8221;:&#8221;&#8221;,&#8221;cvss&#8221;:{&#8220;score&#8221;:0,&#8221;severity&#8221;:&#8221;NONE&#8221;,&#8221;vector&#8221;:&#8221;NONE&#8221;,&#8221;version&#8221;:&#8221;NONE&#8221;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/www.malwarebytes.com\/blog\/news\/2025\/08\/facebook-users-targeted-in-login-phish&#8221;,&#8221;category_name&#8221;:&#8221;News&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2025-08-07T14:12:45&#8243;,&#8221;description&#8221;:&#8221;A few weeks ago we warned our readers of a phishing campaign targeting Instagram users that didn\u2019t resort to the usual links to phishing websites,&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[6,8,12,115,13,33,7,11,5],"class_list":["post-10055","post","type-post","status-publish","format-standard","hentry","category-category_news","tag-cve","tag-cvss","tag-exploit","tag-malwarebytes","tag-news","tag-none","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Facebook users targeted in &#8216;login&#8217; phish_MALWAREBYTES:3A37EE617EDA6A0E95059E2E8A3B71E5 - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=10055\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Facebook users targeted in &#8216;login&#8217; phish_MALWAREBYTES:3A37EE617EDA6A0E95059E2E8A3B71E5 - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2025-08-07T14:12:45&#8243;,&#8221;description&#8221;:&#8221;A few weeks ago we warned our readers of a phishing campaign targeting Instagram users that didn\u2019t resort to the usual links to phishing websites,...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=10055\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2025-08-07T09:53:17+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=10055#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=10055\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"Facebook users targeted in &#8216;login&#8217; phish_MALWAREBYTES:3A37EE617EDA6A0E95059E2E8A3B71E5\",\"datePublished\":\"2025-08-07T09:53:17+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=10055\"},\"wordCount\":777,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"exploit\",\"malwarebytes\",\"news\",\"NONE\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_news\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=10055#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=10055\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=10055\",\"name\":\"Facebook users targeted in &#8216;login&#8217; phish_MALWAREBYTES:3A37EE617EDA6A0E95059E2E8A3B71E5 - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2025-08-07T09:53:17+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=10055#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=10055\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=10055#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Facebook users targeted in &#8216;login&#8217; phish_MALWAREBYTES:3A37EE617EDA6A0E95059E2E8A3B71E5\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Facebook users targeted in &#8216;login&#8217; phish_MALWAREBYTES:3A37EE617EDA6A0E95059E2E8A3B71E5 - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=10055","og_locale":"en_US","og_type":"article","og_title":"Facebook users targeted in &#8216;login&#8217; phish_MALWAREBYTES:3A37EE617EDA6A0E95059E2E8A3B71E5 - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2025-08-07T14:12:45&#8243;,&#8221;description&#8221;:&#8221;A few weeks ago we warned our readers of a phishing campaign targeting Instagram users that didn\u2019t resort to the usual links to phishing websites,...","og_url":"https:\/\/zero.redgem.net\/?p=10055","og_site_name":"zero redgem","article_published_time":"2025-08-07T09:53:17+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=10055#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=10055"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"Facebook users targeted in &#8216;login&#8217; phish_MALWAREBYTES:3A37EE617EDA6A0E95059E2E8A3B71E5","datePublished":"2025-08-07T09:53:17+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=10055"},"wordCount":777,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","exploit","malwarebytes","news","NONE","Security","tapic","Vulnerability"],"articleSection":["category_news"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=10055#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=10055","url":"https:\/\/zero.redgem.net\/?p=10055","name":"Facebook users targeted in &#8216;login&#8217; phish_MALWAREBYTES:3A37EE617EDA6A0E95059E2E8A3B71E5 - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2025-08-07T09:53:17+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=10055#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=10055"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=10055#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"Facebook users targeted in &#8216;login&#8217; phish_MALWAREBYTES:3A37EE617EDA6A0E95059E2E8A3B71E5"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/10055","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=10055"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/10055\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=10055"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=10055"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=10055"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}