
A new phishing campaign is sending victims fake “certificate error” notifications with graphics and formatting that appear to come from Cisco Webex. The goal is to ’ credentials users.
Cisco Webex offers collaboration solutions, helping users organize video conferencing, webinars, online meetings, and share their screens with colleagues and friends. The platform has gained many more users recently due to the unusually high number of remote working.
According to statistics shared by security Abnormal Security, these phishing emails have already reached the inboxes of at least 5,000 targets who use Cisco Webex while working remotely.
Phishing pages on domains that look authentic
Attackers create a sense of urgency with their phishing messages by using graphics and formatting that mimic the automated “SSL certificate error”that Cisco Webex would send to users.
The phishing emails appear to come from the Cisco Webex team and warn targets that they need to verify their accounts, as they have been blocked by the administrator due to Webex Meetings SSL cert errors.
Users are then prompted to click on an embedded “Login” link, which will allow them to log in and unlock their accounts.

“The phishing email includes a SendGrid link that redirects users to a phishing WebEx Cisco site, hosted at https://app-login-webex[.]com,” said researchers at Abnormal Security.
“The domain of this page was recently registered by someone in the Czech Republic and is not associated with Webex or Cisco.”
If users enter their credentials on the phishing page, they will be sent to a server controlled by the hackers.
"The attacker could use the compromised user account to launch other attacks within the organization and against external partners," the researchers explained.
The emails and notifications look very convincing, which is why they could bypass at least some Secure Email Gateways' (SEGs) protections and convince many of the targets to visit the phishing page.

Many platforms that allow remote collaboration and communication have been targeted by hackers during this period.
Recently, fake Microsoft Teams. The goal was to steal Office 365 account credentials.
What makes these attacks even more dangerous is that users receive many notifications from various online collaboration services anyway, so it's easy to get confused.
