Newsletter hackers sign -up forms from international company websites have been used by to disguise phishing emails as official newsletters subscription .
This innovative approach to conducting a phishing campaign also has the ability to fool spam filters built into email servers and clients.
Email-based phishing is used by malicious users who aim to trick their victims into going to websites designed to steal various confidential information, download attachments containing malware, or click on links that redirect to attachments with malware.
The scammers behind this new phishing campaign are sending emails purporting to be from official addresses of global companies, such as Audi, Austrian Airlines, and S-Bahn Berlin, with the title “money for you” in Russian.

At the beginning of the message, a link takes users to a hacked dating website. Then, due to malicious code embedded in the page, users are redirected to a phishing page. There, users are informed that they can take part in a raffle called “The lucky e-mail”, which requires them to complete a series of questions in order to win 3,000 euros.
Once the survey questions are complete, the hackers will also ask potential “winners” about a EUR-RUB exchange fee required to enter the draw.
Victims are taken to a fake payment page where they must enter their credit card details. Once filled in, victims are asked to enter a verification code sent via SMS. Once all steps are completed, all credit card data is in the hands of hackers.
However, the most interesting part is how hackers use the newsletter subscription form from the official websites of various companies to send the phishing emails by adding malicious links to the “Last Name” and “First Name” fields.
