HomeSecurityPhishing: Rapid increase in abuse of legitimate SaaS platforms

Phishing: Sharp increase in abuse of legitimate SaaS platforms

According to a new report from Palo Alto Networks Unit 42, cybercriminals are increasingly abusing legitimate software-as-a-service (SaaS) platforms, such as website builders and personal branding spaces, for malicious phishing sites that steal credentials.

SaaS Phishing

Instead of creating phishing pages from scratch, criminals are abusing legitimate platforms to host their phishing pages. Since these URLs are hosted on legitimate domains, they are harder to detect by phishing detection engines.

See also: Twitter Whistleblower: Horrifying revelations from former executive

Researchers say in the report that they have seen a sharp increase in phishing attacks that abuse SaaS platforms. To put it in numbers, we're talking about a 1,100% increase from June 2021 to June 2022.

This increase is due to the advantages of using SaaS for phishing attacks. These include avoiding alerts from email security systems and high availability, while attackers do not need to learn how to code to create legitimate-looking sites. In addition, because SaaS platforms simplify the process of creating new sites, phishing attack actors can easily switch to different themes, scale or diversify their operations, and respond quickly to reports and takedowns.

Phishing: Sharp increase in abuse of legitimate SaaS platforms
Phishing: Sharp increase in abuse of legitimate SaaS platforms

Unit 42: Abuse of legitimate services for phishing

Unit 42 researchers have divided the platforms abused by hackers into six categories: file sharing and hosting sites, form and survey builders, website builders, note-taking and documentation platforms, and personal portfolio spaces.

Palo Alto Networks' filtering systems recorded an increase in abuse across all SaaS platform categories, but the largest increases were seen in website builders, collaboration platforms, and form builders.

See also: CISA: Critical vulnerability in PAN-OS is being used for attacks

In 2021, Cyren reported increased abuse of “typeform.com” for phishing, an earlier report from Trend Micro mentioned “123formbuilder.com”, “formtools.com” and “smartsurvey.co.uk”, while Cofense highlighted abuse of “Canva.com”.

How the services are used;

The Unit 42 report explains that in many cases, phishing attack vectors host credential theft pages directly on the services compromised. They send an email to targets containing a URL that leads to the specific phishing page.

In other cases, the malicious landing pages hosted on the compromised services do not contain the credential theft forms themselves. Instead, they take the victim through another redirection step to another website.

“In the event that the final credential theft page is removed, the attacker can simply change the link and point to a new theft , maintaining the effectiveness of the original campaign,” the researchers report.

See also: Over 80,000 Hikvision cameras vulnerable to critical vulnerability

Phishing: Sharp increase in abuse of legitimate SaaS platforms

Abuse of SaaS platforms for phishing attacks will continue

Stopping abuse of legitimate SaaS platforms will be very difficult, as implementing aggressive email on these services is not an option. This is precisely what makes them so suitable for phishing campaigns.

Therefore, you should be very careful with the emails you receive. If you receive messages asking you to do something quickly or something that seems strange to you, avoid clicking on embedded links or buttons. Instead, use a search engine to locate the official website of the potentially fake platform.

Whenever you are asked to enter account , make sure you are on the legitimate website URL before you start typing into the form boxes.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS