Threat actors abused Meta’s Business Manager partner request feature to send phishing emails from the legitimate address noreply@business.facebook.com, giving the campaign unusual credibility for businesses that use Facebook or Instagram. Huntress reported the operation evolved from a May variant that used Google Sites and a fake Meta Agency Partner Program page into a June campaign that redirected targets through a fraudulent Facebook Messenger chatbot and Netlify-hosted phishing pages displayed via sw[.]run framing.
The phishing flow collected Meta account credentials, MFA codes, personal information, and identity documents, then exfiltrated the stolen data to Telegram bot channels. Huntress observed Vietnamese-language strings in the exfiltration process and identified a Telegram bot named @bulondondam / data1mdobot, indicating possible Vietnamese origin or shared phishkit infrastructure; Meta later added controls to block the specific abuse path, after which the activity subsided.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
After the abuse was identified, Meta implemented controls that blocked this specific phishing mechanism, and the attacks subsided according to Huntress.
Huntress disclosed that the phishing workflow collected Meta credentials, MFA codes, personal details, and identity documents, then exfiltrated them to Telegram bot channels. The researchers also noted Vietnamese-language strings and a Telegram bot named @bulondondam / data1mdobot as indicators of possible Vietnamese origin or phishkit provenance.
In June 2026, the threat actor evolved the operation to abuse Meta’s business partner request mechanism so phishing emails were sent from noreply@business.facebook.com, directing victims through a fake Facebook Messenger chatbot and Netlify-hosted phishing pages framed via sw[.]run.
Huntress reported that an earlier variant of the campaign in May 2026 used Google Sites and a fake Meta Agency Partner Program page to target businesses using Facebook or Instagram.
Check Point reported a large-scale phishing campaign that abused Facebook Business Suite invitation features to send deceptive emails from the legitimate facebookmail.com domain. The operation sent more than 40,000 phishing emails to over 5,000 customers across the U.S., Europe, Canada, and Australia, using fake Facebook Business pages and phishing sites including vercel.app-hosted pages to steal credentials.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.