IOCs for phishing campaign using BitM pages

Sep 23, 2025 ยท 1 min read

This active browser-in-the-middle (BitM) phishing campaign impersonates Meta and Facebook. It has been observed using copyright-infringement notices as email lures, followed by redirect chains that lead targets to BitM pages.

Activity dates back to at least April 2025, with new domains and URLs continuing to appear. Some variants shorten the chain by linking directly to the phishing page.

Read the full Unit 42 report and indicators โ†’