HomeSecuritySophisticated phishing scam detected

Sophisticated phishing scam detected

Old-Email-Credentials-Phishing-Attack-Redesigned-by-Cybercriminals

The security researcher at Trusteer, Amit Klein, discovered a phishing scam based on an earlier campaign and targeting primarily corporate users.

Attackers aim to intercept email account login credentials in order to gain access to them, subsequently leveraging the victims' contact list or conducting searches for sensitive documents, passwords, and other information.

The deceptive emails sent to users only state the following:

“Hello, Please check the docs I have attached to you”, urging users to check the attached files.

The attachment opens a page that contains a link displayed with the text “downloaded attached”. As is evident, the attackers' primary language is not English, however many users may click the link to download the attachment. The victims are then redirected to a phishing page hosted on a compromised website.

The scammers then ask users to select email and enter their login information. Users can choose between Yahoo, AOL, Gmail, Windows Live, or “other email services.”

After entering their details, users are informed that the main server is busy and are then redirected to the official Google Drive.

For more details on this specific campaign, check out Trusteer. If you have been a victim of the attack, change your password immediately and be on the lookout for any suspicious emails that may appear in your inbox.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS