HomeSecurityOffice 365: Phishing campaign targets users after lockdown!

Office 365: Phishing campaign targets users after lockdown!

Researchers are warning of a new phishing campaign targeting Office 365 users returning to work after the lockdown. Hackers are continuing to exploit the COVID-19, adapting their techniques to the current situation. The attack techniques they adopt depend on the situation of businesses in each region. For example, in places where COVID-19 is spreading at an alarming rate, cybercriminals are using “bait” related to the virus. In other areas where the pandemic is under control, while employees are returning to their jobs, hackers are targeting them with emails that supposedly provide educational resources about the Coronavirus.

Office 365-campaign

As businesses reopen, COVID-19 continues to pose a threat, and organizations are implementing programs and new workplace rules to prevent new infections. To prepare their employees for this new “normal,” many organizations are holding webinars and short training courses in an effort to explain to their employees the limitations and requirements of the new conditions. Cybercriminals are constantly on the lookout for new opportunities, so it’s no surprise that researchers have identified cybercriminals sending phishing emails and malicious filesthat purport to be educational and training materials about COVID-19. The phishing campaign is targeting Office 365 users, with spam emails that include a link to sign up for training. The link redirects users to a malicious page designed to trick them into giving up credentials .

Office 365 users

CheckPoint researchers said that attacks related to the pandemic are decreasing. Specifically, in June, attacks averaged about 130,000 per week, a 24% decrease compared to the corresponding weekly average in May. Researchers also observed new phishing campaigns that use extraordinary events as bait, including the Black Lives Matter (BLM) movement.

In early June, when numerous protests took place worldwide, due to the killing of African-American George Floyd by a “white” police officer, CheckPoint researchers
discovered a spam campaign related to the movement. The emails sent distribute the Trickbot as a malicious doc file with the format, “e-vote_form _ ####. Doc” (# = digit). The emails are sent with subjects such as “Have your say on Black Lives Matter”, “Leave an anonymous comment on Black Lives Matter” or “Vote anonymously for Black Lives Matter”. Upon opening the spam emails and clicking on the attachment, users are redirected to a page claiming to provide an Office update, which in fact links to two malicious URLs that load the Trickbot malware.


CheckPoint researchers also noted that due to rising unemployment, cyberattacks related to job resumes, where malicious files appear in the form of resumes, have escalated in the US and Europe. Finally, the researchers report that the number of malicious files detected has doubled in the last two months, while one in 450 malicious files is a resume-related scam targeting job seekers.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS