Zscaler ThreatLabz identified six Facebook phishing domains registered on 02/13/2011 by the same individual in China. The domains host identical fake Facebook login pages that capture user credentials before redirecting victims to legitimate Facebook or Google. The campaign leverages fast-flux DNS with rapidly rotating IP addresses and a shared DNS server (fbnameserver.com) previously tied to other Facebook phishing operations, making takedowns and blocklisting difficult.
1 post
Facebook Phishing Attacks: How Credential Theft Works