So this is something I figured out but it's probably not that original. Basically you find a Fb profile that isn't privacy protected. Then you create an email address with their name. Then you create a mock Fb page that looks exactly like theirs. Same pictures, state, hometown, etc. Then you friend request all their friends. A lot them will most likely friend you back. They will be thinking you are that person and probably think what would be the harm in accepting a friend request? Now because they think you are a friend of theirs that they know they will be more likely to click on a malicious link you send. Use Zphisher to create a phishing page and shorten the link using goo.by or ggle.io maybe. Look at their page and see what they are interested in. If they like a musician say something like "Guess who died? Your favorite singer." and send them the message with the link attached. Or send them a message saying something like "Is this you?". Then when they click on the link and get sent to the facebook login page if they are dumb they'll just think they got logged out for some reason and type in credentials hopefully. I still need to polish this method. If only I knew how to deliver rats through facebook messenger...I think this is a good way to get someone to click on a link though. I would appreciate if someone could help me with how to deliver a rat using this technique.