Phishing Kit Abuses Open Graph to Target Social Media Users

Researchers at Cyble warn that a phishing kit is abusing the Open Graph (OG) protocol to target social media users.
The Open Graph protocol, originally developed by Facebook in 2010, allows users to control the content preview that’s displayed when a link is posted on social media.
The phishing kit, dubbed “OG Spoof,” abuses this feature to post malicious links that appear legitimate. It does this by using one link to display a preview on social media, and a different link to redirect users to the phishing site.
“The toolkit leveraged Open Graph spoofing techniques, allowing attackers to manipulate the preview of web pages represented on social media platforms. This manipulation is executed through a convenient Telegram bot, which enables attackers to alter the metadata associated with URLs. One of the toolkit’s key features was its ability to generate links—often shortened URLs—that appear to originate from trusted sources. This deceptive tactic exploits Open Graph metadata, making it easier for attackers to lure unsuspecting victims into clicking on harmful links.”
Cyble concludes that OG Spoof and similar phishing kits make it easier for unskilled threat actors to launch sophisticated attacks.
“Such ready-made toolkits lower the barrier to entry, attracting both proficient and new actors seeking financial gain through these tactics,” the researchers write. “Such kits also simplify spear-phishing, a key initial attack vector used by Advanced Persistent Threat (APT) groups to deliver malware. Moreover, with the rise of cryptocurrency scams and fraudulent activity on platforms like X (formerly Twitter), including schemes involving high-profile accounts and fake giveaways, these toolkits are likely to be leveraged in such campaigns, making caution paramount.”
KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.
Cyble has the story.
Free Phishing Security Test
Would your users fall for convincing phishing attacks? Take the first step now and find out before bad actors do. Plus, see how you stack up against your peers with phishing Industry Benchmarks. The Phish-prone percentage is usually higher than you expect and is great ammo to get budget.

Here’s how it works:
- Immediately start your test for up to 100 users (no need to talk to anyone)
- Select from 20+ languages and customize the phishing test template based on your environment
- Choose the landing page your users see after they click
- Show users which red flags they missed, or a 404 page
- Get a PDF emailed to you in 24 hours with your Phish-prone % and charts to share with management
- See how your organization compares to others in your industry
PS: Don’t like to click on redirected buttons? Cut & Paste this link in your browser: https://info.knowbe4.com/phishing-security-test-partner?partnerid=001a000001lWEoJAAW