Phishers Exploit Salesforce’s Email Services Zero-Day in Targeted Facebook Campaign

Share:

A sophisticated Facebook phishing campaign has been observed exploiting a zero-day flaw in Salesforce’s email services, allowing threat actors to craft targeted phishing messages using the company’s domain and infrastructure.

Those phishing campaigns cleverly evade conventional detection methods by chaining the Salesforce vulnerability and legacy quirks in Facebook’s Web Games platform, Guardio Labs researchers Oleg Zaytsev and Nati Tal said in a report shared with The Hacker News.

The email messages masquerade as coming from Meta, while being sent from an email address with a @salesforce.com domain. They seek to trick recipients into clicking on a link by claiming that their Facebook accounts are undergoing a comprehensive investigation due to suspicions of engaging in impersonation.

The goal is to direct users to a rogue landing page that’s designed to capture the victim’s account credentials and two-factor authentication (2FA) codes. What makes the attack notable is that the phishing kit is hosted as a game under the Facebook apps platform using the domain apps.facebook[.]com.

So it’s a no-brainer why we’ve seen this email slipping through traditional anti-spam and anti-phishing mechanisms. It includes legit links (to facebook.com) and is sent from a legit email address of @salesforce.com, one of the world’s leading CRM providers, the researchers explained.

It’s worth pointing out that Meta retired the Web Games feature in July 2020, although it’s possible to retain support for legacy games that were developed prior to its deprecation.

While sending out emails using a salesforce.com entails a validation step, Guardio Labs said the scheme cleverly gets around these protective measures by configuring an Email-to-Case inbound routing email address that uses the salesforce.com domain and setting it up as the organization-wide email address.

This triggers the verification flow that sends the email to this routing address, ending up as a new task in our system, the researchers said, pointing out it leads to a scenario where a salesforce.com email address can be verified simply by clicking on the link accompanying the request to add the actor-controlled address.

From here you just go on and create any kind of phishing scheme, even targeting Salesforce customers directly with these kinds of emails. And the above will end up in the victim’s inbox, bypassing anti-spam and anti-phishing mechanisms, and even marked as Important by Google.

Following responsible disclosure on June 28, 2023, Salesforce addressed the zero-day as of July 28, 2023, with new checks that prevent the use of email addresses from the @salesforce.com domain.

The development comes as Cofense warned of increased phishing activity that employs Google Accelerated Mobile Pages (AMP) URLs to bypass security checks and conduct credential theft.

The prevalence of phishing attacks and scams remains high, with bad actors continuously testing the limits of email distribution infrastructure and existing security measures, the researchers said.

A concerning aspect of this ongoing battle is the exploitation of seemingly legitimate services, such as CRMs, marketing platforms, and cloud-based workspaces, to carry out malicious activities.

 

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

 

(c) Thin

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
10:28 pm, Jul 5, 2025
weather icon 20°C
L: 18° | H: 21°
scattered clouds
Humidity: 79 %
Pressure: 1010 mb
Wind: 10 mph SW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 40%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:50 am
Sunset: 9:19 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 10:00 pm
weather icon
18° | 21°°C 1 mm 100% 11 mph 85 % 1010 mb 0 mm/h
Mon Jul 07 10:00 pm
weather icon
13° | 20°°C 1 mm 100% 13 mph 92 % 1015 mb 0 mm/h
Tue Jul 08 10:00 pm
weather icon
13° | 24°°C 0 mm 0% 11 mph 78 % 1020 mb 0 mm/h
Wed Jul 09 10:00 pm
weather icon
15° | 26°°C 0 mm 0% 7 mph 67 % 1022 mb 0 mm/h
Thu Jul 10 10:00 pm
weather icon
18° | 30°°C 0 mm 0% 5 mph 55 % 1023 mb 0 mm/h
Tomorrow 1:00 am
weather icon
19° | 20°°C 0 mm 0% 8 mph 80 % 1010 mb 0 mm/h
Tomorrow 4:00 am
weather icon
18° | 18°°C 0 mm 0% 6 mph 85 % 1009 mb 0 mm/h
Tomorrow 7:00 am
weather icon
20° | 20°°C 0 mm 0% 7 mph 80 % 1006 mb 0 mm/h
Tomorrow 10:00 am
weather icon
19° | 19°°C 1 mm 100% 7 mph 85 % 1005 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
19° | 19°°C 1 mm 100% 9 mph 79 % 1005 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
19° | 19°°C 1 mm 100% 10 mph 77 % 1005 mb 0 mm/h
Tomorrow 7:00 pm
weather icon
21° | 21°°C 1 mm 100% 11 mph 53 % 1005 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
18° | 18°°C 0.44 mm 44% 9 mph 60 % 1007 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€91,776.88
0.30%
Ethereum(ETH)
€2,130.82
0.74%
Tether(USDT)
€0.85
0.01%
XRP(XRP)
€1.88
-0.38%
Solana(SOL)
€124.87
0.29%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.139283
0.99%
Shiba Inu(SHIB)
€0.000009
0.66%
Pepe(PEPE)
€0.000008
1.12%
Scroll to Top