Phishers Exploit Salesforce’s Email Services Zero-Day in Targeted Facebook Campaign

Teilen:

A sophisticated Facebook phishing campaign has been observed exploiting a zero-day flaw in Salesforce’s email services, allowing threat actors to craft targeted phishing messages using the company’s domain and infrastructure.

Those phishing campaigns cleverly evade conventional detection methods by chaining the Salesforce vulnerability and legacy quirks in Facebook’s Web Games platform, Guardio Labs researchers Oleg Zaytsev and Nati Tal said in a report shared with The Hacker News.

The email messages masquerade as coming from Meta, while being sent from an email address with a @salesforce.com domain. They seek to trick recipients into clicking on a link by claiming that their Facebook accounts are undergoing a comprehensive investigation due to suspicions of engaging in impersonation.

The goal is to direct users to a rogue landing page that’s designed to capture the victim’s account credentials and two-factor authentication (2FA) codes. What makes the attack notable is that the phishing kit is hosted as a game under the Facebook apps platform using the domain apps.facebook[.]com.

So it’s a no-brainer why we’ve seen this email slipping through traditional anti-spam and anti-phishing mechanisms. It includes legit links (to facebook.com) and is sent from a legit email address of @salesforce.com, one of the world’s leading CRM providers, the researchers explained.

It’s worth pointing out that Meta retired the Web Games feature in July 2020, although it’s possible to retain support for legacy games that were developed prior to its deprecation.

While sending out emails using a salesforce.com entails a validation step, Guardio Labs said the scheme cleverly gets around these protective measures by configuring an Email-to-Case inbound routing email address that uses the salesforce.com domain and setting it up as the organization-wide email address.

This triggers the verification flow that sends the email to this routing address, ending up as a new task in our system, the researchers said, pointing out it leads to a scenario where a salesforce.com email address can be verified simply by clicking on the link accompanying the request to add the actor-controlled address.

From here you just go on and create any kind of phishing scheme, even targeting Salesforce customers directly with these kinds of emails. And the above will end up in the victim’s inbox, bypassing anti-spam and anti-phishing mechanisms, and even marked as Important by Google.

Following responsible disclosure on June 28, 2023, Salesforce addressed the zero-day as of July 28, 2023, with new checks that prevent the use of email addresses from the @salesforce.com domain.

The development comes as Cofense warned of increased phishing activity that employs Google Accelerated Mobile Pages (AMP) URLs to bypass security checks and conduct credential theft.

The prevalence of phishing attacks and scams remains high, with bad actors continuously testing the limits of email distribution infrastructure and existing security measures, the researchers said.

A concerning aspect of this ongoing battle is the exploitation of seemingly legitimate services, such as CRMs, marketing platforms, and cloud-based workspaces, to carry out malicious activities.

 

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

 

(c) Thin

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
2:05 pm, Mai 18, 2025
Wetter-Symbol 16°C
L: 14° | H: 17°
wenige Wolken
Luftfeuchtigkeit: 57 %
Druck: 1019 mb
Wind: 7 mph NE
Windböe: 10 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 17%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 5:04 am
Sonnenuntergang: 8:49 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
14° | 17°°C 0 mm 0% 7 mph 66 % 1020 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
11° | 18°°C 0 mm 0% 11 mph 82 % 1022 mb 0 mm/h
Di. Mai 20 10:00 pm
Wetter-Symbol
9° | 20°°C 0 mm 0% 8 mph 79 % 1022 mb 0 mm/h
Mi. Mai 21 10:00 pm
Wetter-Symbol
12° | 18°°C 1 mm 100% 9 mph 93 % 1019 mb 0 mm/h
Do. Mai 22 10:00 pm
Wetter-Symbol
9° | 17°°C 0 mm 0% 10 mph 63 % 1023 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
16° | 17°°C 0 mm 0% 7 mph 55 % 1020 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
16° | 17°°C 0 mm 0% 6 mph 53 % 1019 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
13° | 13°°C 0 mm 0% 6 mph 66 % 1020 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
12° | 12°°C 0 mm 0% 7 mph 69 % 1020 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 6 mph 82 % 1020 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
12° | 12°°C 0 mm 0% 7 mph 73 % 1021 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
16° | 16°°C 0 mm 0% 8 mph 51 % 1021 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
18° | 18°°C 0 mm 0% 10 mph 45 % 1021 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€93,090.24
0.91%
Ethereum(ETH)
€2,243.86
1.20%
Fesseln(USDT)
€0.90
0.00%
XRP(XRP)
€2.14
1.94%
Solana(SOL)
€153.50
2.35%
USDC(USDC)
€0.90
0.00%
Dogecoin(DOGE)
€0.200507
3.95%
Shiba Inu(SHIB)
€0.000013
3.94%
Pepe(PEPE)
€0.000012
7.53%
Peanut das Eichhörnchen(PNUT)
€0.307724
14.29%
Nach oben scrollen