All posts tagged: phishing

Midnight Blizzard Escalates Spear-Phishing Attacks

Midnight Blizzard Escalates Spear-Phishing Attacks

Microsoft Threat Intelligence has uncovered a new attack campaign by Russian threat actor Midnight Blizzard, targeting thousands of users across over 100 organizations. The attack leverages spear-phishing emails with RDP configuration files, allowing attackers to connect to and potentially compromise the targeted systems. The attack campaign targeted thousands of users in higher education, defense, non-governmental organizations, and government agencies. Dozens of countries have been impacted, particularly in the U.K., Europe, Australia, and Japan, which is consistent with previous Midnight Blizzard phishing campaigns. Phishing emails contained RDP configuration file In the latest Midnight Blizzard attack campaign, victims received highly targeted emails that used social engineering lures relating to Microsoft, Amazon Web Services, and the concept of Zero Trust. According to Microsoft Threat Intelligence, the emails were sent using email addresses belonging to legitimate organizations, gathered by the threat actor during previous compromises. All emails contained a RDP configuration file, signed with a free LetsEncrypt certificate, that included several sensitive settings. When a user opened the file, an RDP connection would be established to an attacker-controlled system. …

Over 5,000 Fake Microsoft Notifications Fueling Email Compromise Campaigns

Check Point’s Harmony Email & Collaboration team detected over 5,000 emails disguised as Microsoft product notifications, which could lead to email extortion, the cybersecurity company said on Oct. 2. The emails stand out for their polished appearance and the inclusion of legitimate links. The announcement comes as part of Cybersecurity Awareness Month, highlighting the ongoing risks posed by phishing attacks. Email scam campaign stands out for polished appearance The emails come from “organizational domains impersonating legitimate administrators,” making them appear as if they came from an internal administrator, colleague, or business partner. The fake emails link to legitimate Microsoft or Bing pages, making it difficult for even security-conscious employees scanning for suspicious URLs to detect the scam. Check Point noted that logging in to a fake email — thereby giving the attacker your login information — can “lead to email account takeover, ransomware, information theft or other negative outcomes.” The team did not provide any information about whether the attackers had succeeded in exploiting anyone so far. In 2023, Check Point found Microsoft was the …

Are Ghost Calls a Problem? Yes, if They Don’t Stop

A ghost call is an incoming call with no one on the other end when you answer it. Sometimes it’s an unrecognized number; other times the caller ID shows “Unknown.” Getting an occasional ghost call is common and nothing to worry about. But persistent ghost calls can be a major concern — particularly for businesses. Here’s why. Frequent ghost calls can tie up phone lines, preventing legitimate calls from reaching the company. This disruption can lead to missed opportunities, frustrated customers, and a potential loss of revenue. Responding to or investigating ghost calls consumes time and resources. Employees may waste time answering these calls instead of focusing on productive tasks. Persistent ghost calls, especially those resulting from malicious activities like port scanning, may indicate poor encryption and security in your phone system. Regular interruptions from ghost calls can lead to frustration and anxiety, straining customer relationships and employee morale. Innocent reasons for ghost calls While these types of calls can be cause for concern, most are accidental and innocent in nature. Let’s explore some of …

Phishing Attacks on Australia Disguised as Atlassian

Enterprises across Australia and the APAC region have been warned that cyber criminals are exploiting popular platforms like Atlassian to launch more convincing phishing attacks on law firms and other corporations. These attacks aim to steal employee credentials and breach company cyber security defences. Ryan Economos, APAC field chief technology officer at email security firm Mimecast, told TechRepublic that such phishing attacks are rare in their use of Atlassian as a cover. But he noted that phishing attacks are becoming increasingly sophisticated, thanks to phishing kits and AI, which make it easier for cyber criminals to execute their activities. Atlassian workspaces, Japanese ISPs, and a compliance cover story Mimecast’s Global Threat Intelligence Report 2024 H1 reported on the emergence of a new phishing tactic that used a compliance update cover story to target law firm employees. The phishing attacks: Leveraged popular local brand Atlassian’s workspaces, as well as other unified workspace platforms, including Archbee and Nuclino, to send employees harmful emails that looked familiar and legitimate. Used device compliance updates as a cover, instructing employees …

Threat Actors Exploit Microsoft Sway to Host QR Code Phishing Campaigns

A new report from cybersecurity company Netskope reveals details about attack campaigns abusing Microsoft Sway and CloudFlare Turnstile and leveraging QR codes to trick users into providing their Microsoft Office credentials to the phishing platform. These campaigns have targeted victims in Asia and North America across multiple segments led by technology, manufacturing, and finance. What is quishing? QR codes are a convenient way to browse websites or access information without the need to enter any URL on a smartphone. But there is a risk in using QR codes: cybercriminals might abuse them to lead victims to malicious content. This process, called “quishing,” involves redirecting victims to malicious websites or prompting them to download harmful content by scanning a QR code. Once on the site, cybercriminals work to steal your personal and financial information. The design of QR codes makes it impossible for the user to know where the code will direct them after scanning. Thomas Damonneville, head of anti-phishing company StalkPhish, told TechRepublic that quishing “is a growing trend” that “is very easy to use …

Android Safe Browsing Feature Rolled Out by Google With Live Threat Protection: How it Works

Google is introducing a new security feature for Android smartphones designed to keep users safe from malicious links while using apps on their handsets. The ‘Android Safe Browsing‘ feature supports third-party apps and will alert users when they access harmful links or websites, according to Android expert Mishaal Rahman. The feature has been spotted on Google’s Pixel phones and Samsung Galaxy handsets. It is expected to roll out to other smartphones via Google Play Services along with the ability to toggle the setting. According to details shared by Rahman via X (formerly known as Twitter) a new Android Safe Browsing page has appeared on some Android smartphones, informing users that the feature can alert them when they browse within supported apps and encounter harmful links and web pages. The description also says that the safe browsing feature can protect users from phishing links. Google is rolling out a new “Android Safe Browsing” page to users that lets you see which apps support the feature as well as a toggle “live threat protection” which enables “more …

QR codes can be phishing scams in disguise, warns the FTC

The Federal Trade Commission (FTC) warned the public against scanning any old QR code in a consumer alerts blog last week. Naturally, the warning comes down to security and privacy — bad actors can put QR codes in inconspicuous places or send them via text or email, then just sit back and wait for a payday in the form of money, logins, or other sensitive information. The New York Times reported that John Fokker, who heads threat intelligence at cybersecurity company Trellix, says Trellix found over “60,000 samples of QR code attacks” in the third quarter this year alone. The Times wrote that the most popular scams involved payroll and HR personnel impersonators and postal scams, among others. Early last year, police in several Texas cities said they’d found fraudulent QR codes placed on parking meters, directing people to a false payment site. To avoid being victimized by a bad code, the FTC suggests ignoring unexpected emails or other messages you weren’t expecting that come with some sort of urgent request. It’s also good to …

North Korea Becomes Epicentre for NFT Thefts via 500 Phishing Domains: SlowMist

North Korea’s notorious Lazarous Group, infamous for triggering cyber-attacks, has yet again come under the limelight, for striking the NFT sector with back-to-back strikes. The group of hackers have launched around 500 phishing domains using which, they are duping unsuspecting victims, who are also enthusiastic NFT buyers. The claims against the Lazarous Group have been noted in the recent report by SlowMist, a blockchain security firm. The report has highlighted that this NFT stealth campaign has been going on for months with the earliest malicious domain having been registered around May-June. NFTs or non-fungible tokens are blockchain-built digital collectibles, most of which are also functional in compatible metaverse experiences. More often than not, NFTs are valuable and their blockchain-based creation transfers the complete ownership of these virtual collectibles to the buyers and are held in crypto wallets. The Lazarous Group has been deploying ‘decoy websites’ pretending to be legit NFT projects, to get them to engage with these infected sites. “Phishing websites will record visitor data and save it to external sites. The hacker records …

Ice Phishing Scams: What Are They and How Can Web3 Users Stay Clear of These Cyber Attacks

The boom in the global fintech industry, has ushered in an era of scammers, armed with high-end tech tools to dupe you out of your hard-earned money. One such advanced scamming technique, especially targeted at the crypto community, is called ‘ice phishing’. In its latest advisory report to the global Web3 sector, cyber research firm CertiK has sounded an alert against the rising cases of ice phishing scams while also outlining preventative measures to keep finances safeguarded. Ice phishing scams are cyber-attacks that manoeuvre Web3 users into manually signing and approving permissions that allow notorious actors to spend their tokens. These permissions usually have to be signed on decentralised finance (DeFi) protocols, that could easily be mock-ups. “The hacker just needs to make a user believe that the malicious address that they are granting approval to is legitimate. Once a user has approved permissions for the scammer to spend tokens, then the assets are at risk of being drained,” CertiK wrote in its report. Once the scammers get this permission, they can transfer the funds …