Guardio Labs details a campaign that uses fake and compromised Facebook accounts to send 100K+ Messenger phishing messages per week, targeting business accounts
Botnet of Facebook Users Launch High-Intent Messenger Phishing Attack on Business Accounts Anthony Spadafora / Tom's Guide : Hackers are using Facebook Messenger to spread password-stealing malware β how to stay safe Vilius Petkauskas / Cybernews.com : Facebook Messenger phishing attack pumps out 100K+ weekly messages The Hacker News : Vietnamese Hackers Deploy Python-Based Stealer via Facebook Messenger Mastodon: @Freemind@mastodon.online : One clever tactic used by the attackers involves deleting the stolen cookies after extracting them.Β This effectively logs the victims out of their own accounts.Β βΒ #Cybersecurity #Meta #FacebookMessenger #Stealer #PhytonΒ βΒ https://cybersec84.wordpress.com/ ... Catalin Cimpanu / @campuscodi@mastodon.social : A Vietnamese threat actor going by the name of MrTonyScam has been conducting expansive Facebook Messenger spam campaigns delivering malware using malicious attachments.Β βΒ https://labs.guard.io/...Β [image] X: @guardiosecurity : π¨Guardio Labs' latest research reveals that #Facebook's Messenger platform is being abused to spread malicious attachments, targeting business pages. Approximately 1 in 70 have been affected by one campaign, originating from a Vietnamese-based group. π² https://medium.com/...
Context & Ripple Effects
This campaign fits a recurring pattern in the related coverage: compromised or trusted-looking social accounts are repurposed as malware distribution channels. Earlier reporting described verified Meta accounts impersonating the company to run malicious ads, while later coverage traced hijacked Facebook pages promoting fake AI services.
The distinguishing risk here is direct outreach to business accounts at scale. The reported cookie deletion after theft adds an operational impact: victims can lose access at the same time attackers gain it.
First-order effects
- Business-account users receiving the Messenger lures face credential and session-cookie theft through malicious attachments; cookie deletion can immediately force victims out of their own accounts.
- Facebook must contend with abuse originating from both fabricated accounts and compromised legitimate ones, making account provenance and message-volume signals central to detection.
Second-order effects
- Businesses using Facebook pages or Messenger as customer-contact channels may need to treat unexpected attachments and account lockouts as potential compromise events, not merely spam.
- The campaign reinforces the value of already-compromised social accounts as distribution infrastructure, the same underlying route seen in hijacked pages used to promote malware through ads.
Third-order effects
- If account takeover continues to supply trusted identities for phishing, platform safety shifts from removing individual malicious messages toward protecting account recovery, session integrity, and distribution controls.
- This is another instance of distribution-layer liability: platforms that enable high-volume business communication also become enforcement points when trusted accounts are weaponized.
The trend: Social-platform account compromise is increasingly being used to turn trusted identities and messaging channels into scalable malware-distribution infrastructure.