HomeSecurityCredential theft via fake notifications from Cisco Webex

Credential theft via fake notifications from Cisco Webex

 Cisco Webex

A new phishing campaign is sending victims fake “certificate error” notifications with graphics and formatting that appear to come from Cisco Webex. The goal is to ’ credentials users.

Cisco Webex offers collaboration solutions, helping users organize video conferencing, webinars, online meetings, and share their screens with colleagues and friends. The platform has gained many more users recently due to the unusually high number of remote working.

According to statistics shared by security Abnormal Security, these phishing emails have already reached the inboxes of at least 5,000 targets who use Cisco Webex while working remotely.

Phishing pages on domains that look authentic

Attackers create a sense of urgency with their phishing messages by using graphics and formatting that mimic the automated “SSL certificate error”that Cisco Webex would send to users.

The phishing emails appear to come from the Cisco Webex team and warn targets that they need to verify their accounts, as they have been blocked by the administrator due to Webex Meetings SSL cert errors.

Users are then prompted to click on an embedded “Login” link, which will allow them to log in and unlock their accounts.

 Cisco Webex

“The phishing email includes a SendGrid link that redirects users to a phishing WebEx Cisco site, hosted at https://app-login-webex[.]com,” said researchers at Abnormal Security.

“The domain of this page was recently registered by someone in the Czech Republic and is not associated with Webex or Cisco.”

If users enter their credentials on the phishing page, they will be sent to a server controlled by the hackers.

"The attacker could use the compromised user account to launch other attacks within the organization and against external partners," the researchers explained.

The emails and notifications look very convincing, which is why they could bypass at least some Secure Email Gateways' (SEGs) protections and convince many of the targets to visit the phishing page.

Credential theft via fake notifications from Cisco Webex

Many platforms that allow remote collaboration and communication have been targeted by hackers during this period.

Recently, fake Microsoft Teams. The goal was to steal Office 365 account credentials.

What makes these attacks even more dangerous is that users receive many notifications from various online collaboration services anyway, so it's easy to get confused.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS