A very clever phishing campaign targets bloggers and website owners with emails that pretend to come from their hosting provider who wants to upgrade their domain to use secure DNS (DNSSEC).

Since it is possible to determine who hosts a domain for a website via WHOIS records, IP addresses and HTTP headers, email fraud is highly targeted and impersonates the specific hosting company used by a website.
In a new Sophos report, researchers explain how scammers use this WHOIS information to send targeted emails that “impersonate/pose as” WordPress, NameCheap, HostGator, Microsoft Azure, and other well-known hosting companies.
The security firm detected the scam for the first time when it received a phishing message supposedly from WordPress, which hosts the NakedSecurity blog.

The Domain Name System (DNS) is the technology that is analogous to the real “phone directory”. It maps the official domain names to the corresponding IP address of the server where the website is hosted.
There is a newer protocol, DNSSEC, which exists to provide additional security for DNS queries and responses. This capability is usually implemented as protection by domain hosting providers to prevent DNS data breaches.
These phishing messages claim that the website's DNS provider will upgrade its DNS to secure DNS (DNSSEC), but you must click a link to enable this enhanced security feature.
The Sophos report explains that DNSSEC is not something website owners typically install themselves.
“You’ve probably never set up DNSSEC or used it yourself, because it was typically a feature that service providers used to keep DNS databases intact when exchanging data with other DNS servers,” the report explains.
Considering that most independent bloggers rarely have a reason to check DNSSEC, spammers exploit their curiosity and fear through this campaign.
Once they click on the malicious links in the email, a “suddenly believable” Update Assistant page is created.

Interestingly, these pages are dynamically generated based on base64 encoded GET parameters in the URL. These parameters instruct the backend to render the page with the appropriate name, logo , and URL of the client website.
Some prominent hosting company names that “impersonated” are HostGator, HostMonster, KonaKart, Linode, Magento, Microsoft Azure, NameCheap and Network Solutions.
The goal of this phishing campaign is to steal credentials from unsuspecting users instead of offering them any legitimate DNSSEC protection service.
Once the user enters their credentials, the malicious website pretends to initiate a series of installation and “update” sequences, attempting to mimic installation through various tools.

Users are informed that once the update is completed, they will be redirected to their website. However, this does not happen, possibly due to a programming error on the part of the scammers.
“As you can see, the scammers claim that you will be redirected to their own website at the end of the process, but instead you end up with a URL that includes your website name preceded by the name of the scammers’ fake set of websites. This generates a 404 error – what we can’t tell you is whether the scammers made a programming error and accidentally redirected you to https://[THEIRDOMAIN]/your.example instead of directly to https://your.example or whether they wanted this all along, so as not to redirect you directly to their own login page, which would look suspicious given that you have already entered username and password,” Sophos says in its report.
As a general rule, to protect against scams like these, email recipients should be very careful about the links they click in an email and especially when entering credentials into unknown websites and systems.
Enabling two-factor can also help prevent phishing attacks that attempt to steal login credentials.
Source information: Sophos
