IOCs for phishing campaign using BitM pages
Sep 23, 2025
ยท
1 min read
This active browser-in-the-middle (BitM) phishing campaign impersonates Meta and Facebook. It has been observed using copyright-infringement notices as email lures, followed by redirect chains that lead targets to BitM pages.
Activity dates back to at least April 2025, with new domains and URLs continuing to appear. Some variants shorten the chain by linking directly to the phishing page.