Phishing attacks have begun to exploit Basecamp in an attempt to distribute malware and steal credentials.
Basecamp is an online project management solution that allows people to collaborate, talk to each other, create documents, and share files.

Documents can be formatted with HTML links, images, and text. Additionally, Basecamp allows users to upload any file to a project, including some formats that are typically considered unsafe (executables, JavaScript files, etc.).
To share files, users can create a public link that allows people outside the organization to preview and download the file.
If users click on this link, they will be taken to a page that previews the file. There is also a link that allows them to download the file to their computer.
With Basecamp, users can distribute any type of file.

Basecamp is used to distribute malware executables
Security researchers found that cybercriminals are distributing BazarLoaderusing public Basecamp download links.
BazarLoader is a backdoor Trojan, developed by the TrickBot gang, that targets large organizations. Once installed, BazarLoader will deploy Cobalt Strike beacons that allow crooks to gain access to the organizations' network and deploy the Ryuk ransomware.
Abuse of secure services, such as Basecamp, to host malicious files and phishing pages is a common occurrence. Users feel a sense of security, seeing a legitimate service. Therefore, it is easy to be deceived.
Additionally, according to the researchers, the use of Basecamp URLs allows for the creation of carefully designed and targeted campaigns. Users believe that the file they receive comes from their Basecamp project, thus giving the criminal access to the network.
Therefore, all files and download links should be treated as suspicious, regardless of their origin. Hackers use legitimate services to be as convincing as possible.

Basecamp is used in phishing campaigns
In a report by cybersecurity firm Cyjax, researcher Will Thomas explains that some phishing campaigns use Basecamp to host pages that redirect users to phishing sites.
Because Basecamp is legal, it is considered trustworthy and bypasses security solutions.
“This technique is effective because Basecamp and Google Cloud hosting are often used for business operations and are considered secure solutions by most detection systems. Cloud platforms also maintain the anonymity of their users and can be quickly set up. It is difficult for SOC analysts to identify them as a threat because the traffic to and from these services appears legitimate,” Thomas explains in his report.
Recently, Thomas discovered a phishing campaign that used a Basecamp document to redirect users to an Office 365 phishing page. There, the user must enter their credentials.
Additionally, according to Bleepingcomputer, use hackers Basecamp because they can make any edits to the intermediate pages (the ones that redirect users to phishing sites). If there is a problem with a particular phishing page, hackers can simply log in to Basecamp and modify the intermediate page to redirect the user to a different phishing page. This way, hackers can continue attacks even if researchers manage to take down a phishing page.
