HomeSecurityHackers exploit Omicron mutation for phishing attacks

Hackers exploit Omicron mutation for phishing attacks

Cybercriminals carrying out phishing attacks have begun exploiting the new COVID-19 mutation, Omicron, and using it as a lure to attract the attention of their victims.

COVID-19 phishing

It is very common for threat actors to exploit current events. COVID-19 is the perfect bait, as it has been the main topic of conversation around the world for about two years. Furthermore, it is a situation that causes fear in many people, and this is a key element in successfully carrying out a phishing attack. When people are in a panic, they are more likely to rush to open an email without thinking first.

See also: A simple technique enhances phishing campaigns to spread malware

Phishing threat actors are now exploiting the Omicron variant, whose emergence has caused concern due to fears of high transmissibility and possible vaccine ineffectiveness. At this stage, scientists are trying to see how serious this new variant is and people are following the developments.

Criminals are exploiting this turmoil and targeting users with phishing attacks.

COVID-19, Omicron: Phishing campaign targets the United Kingdom

UK consumer protection organisation “Which?” has published two sample phishing emails, purporting to come from theNHSUK’s and warning recipients about the new Omicron variant.

See also: Phishing campaign used Samsung to target cybersecurity companies

These emails claim that the Service is offering a free Omicron PCR test . To make the emails appear legitimate, the hackers use the malicious address “ contact-nhs@nhscontact.com ” to distribute the messages .

If the recipient clicks on the embedded “Get it now” button or taps on the URL provided in the email, they will be taken to a fake NHS site.

Omicron variant

Victims are then asked to provide their full name, date of birth, home address, mobile phone number and email address.

Finally, they are asked to pay £1.24 ($1.65), an amount that is supposed to cover the cost of delivering the test results.

The purpose of the phishing campaign is not to steal the amount itself, but the victim's payment details, such as e-banking credentials or credit card details.

See also: IKEA cyberattack: Phishing emails targeted employees

During this step, the victim is also asked to enter their mother's name, which criminals could use to bypass security questions during a subsequent account takeover attempt.

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS