That Facebook Messenger update could be a phishing scam

Facebook Messenger App
(Image credit: DenPhotos / Shutterstock)

The Singapore-based cybersecurity firm Group-IB has discovered a large-scale phishing campaign which is being used to target Facebook Messenger users worldwide.

The company's Digital Risk Protection (DRP) analysts have found evidence proving that users in more that 80 countries in Europe, Asia, the Middle East and North and South America have been affected by the campaign which uses fake ads promoting an updated version of Facebook Messenger to harvest users' login credentials.

So far, Group-IB has discovered almost 1,000 fake Facebook profiles being used in the scheme that first appeared on its radar last summer when its DRP analysts in Asia and Europe began detecting traces of the same fraudulent campaign.

Head of the digital risk protection department at Group-IB in Europe, Dmitriy Tiunkin provided further insight on why internet users often fall for these types of scams online in a press release, saying;

“The internet has made people abandon critical thinking. Living in the era of instant-everything, clicking on an attractive ad, proposal, headline became a natural human reflex. This didn’t come unnoticed by fraudsters who have been relentlessly feeding on users’ carelessness. It is up to brands to set things straight in this endless stand-off by ensuring that their name isn’t used to trick unsuspecting customers into a scam, with digital risk protection services serving as a silver bullet in this case.”

Facebook Messenger scam campaign

While this new Facebook Messenger scam campaign originated in the summer of 2020, it began picking up steam in April of this year when the number of posts on the social network inviting users to install the latest Messenger update reached 5,700.

In order to appear more legitimate, the cybercriminals behind the campaign registered for accounts on Facebook with names that mimic the real app such as Messanger, Meseenger, Massengar while using the official Facebook Messenger logo as their profile picture. At the same time though, they also used link shortening services like bit.ly to bypass Facebook's scam filters.

If a user clicks on the link in one of these fake ads, they are taken to a fake Facebook Messenger website with a login form used by the scam campaign to harvest their credentials. The cybercriminals used a number of different free web hosting services to create these fake login pages and they even offered Facebook users non-existent features such as being able to see who visited their profiles or to view deleted messages to entice them to login.

Group-IB has informed Facebook regarding this campaign but until it is shut down, users of the social network should be on the lookout for these fake ads and avoid clicking on shortened URLs  as they can lead to phishing pages or even malware. Misspellings in brand names and web addresses are another thing to look out for when trying to identify scam campaigns online.

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
unblock facebook with vpn
A new Facebook phishing campaign looks to trick you with emails sent from Salesforce
Smartphone with new logo X twitter app background. Application twitter old blue bird change X black and white new.
Phishing campaign targets prominent X users, accounts at risk
Paper craft illustration of a suspicious email that contains a snake
How to spot a phishing email
Google Pixel Scam Detection warning
Common internet scams and how to avoid them
Malware worm
Coordinated global mobile malware campaign targets banking apps and cryptocurrency platforms
An iPhone sitting on a wooden table
Millions at risk as malicious PDF files designed to steal your data are flooding SMS inboxes - how to stay safe
Latest in Security
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Representational image depecting cybersecurity protection
GitLab has patched a host of worrying security issues
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
AI agents can be hijacked to write and send phishing attacks
China
Volt Typhoon threat group had access to American utility networks for the best part of a year
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
Latest in News
Google Pixel 8a in aloe green showing
Google Pixel 9a benchmark link teases the performance of the upcoming mid-ranger
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 17 (game #1148)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 17 (game #379)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 17 (game #645)
Apple iPhone 16 Pro HANDS ON
Leaked iPhone 17 dummy units may have given us our best look yet at all four models
A super close up image of the Google Gemini app in the Play Store
It's official: Google Assistant will be retired for phones this year, with Gemini taking over