A new phishing campaign is pretending to be a well-known security company, sending its victims emails about online security.

Over time, users become more and more aware of the different forms of phishing scams, so malicious actors have to become more and more creative in order to outsmart them.
And it seems that this particular incident, discovered by the company Cofense, is one such attempt, as it pretends to be a “Security Awareness Training” email from KnowBe4.
As phishing attacks become more common, cybersecurity companies areoffering training on them, as well as simulation tests to see how well employees can spot malicious emails.
A popular security company is KnowBe4, which offers phishing training and simulation testing
This new phishing campaign, analyzed by Cofense and initially reported by KnowBe4, involves emails pretending to be from KnowBe4, reminding the company's customers to log in to attend phishing training.
These emails use the subject “Training Reminder: Due Date” and inform the recipient to log in to the “Security Awareness Training” before it expires within 24 hours.

An interesting detail of the email is that it warns that the link does not lead to the typical phishing training platform, but to an external website.
The reason behind this action is to appear more trustworthy to the user, who will obviously notice that the link does not lead to the security company's website and thus gain their trust.
If a user clicks on the URL, they will be taken to an address using the Russia .ru TLD , where they will be asked to sign in with their Outlook credentials to begin the training. Once they do, they will be asked to enter more information such as username, email, name, date of birth, address, and once again, a password.
Once malicious actors obtain this information, they can use it for more targeted attacks, such as BEC scams or to access the victim's network
For this reason, you should always be careful with the emails you receive, be especially suspicious when you are asked for a lot of information, and do not click on links that seem suspicious.
