centristic
  • Solutions
    • Governance, Risk and Compliance Services
    • Identity and Access Management Service
    • Data Protection & Privacy
    • Cyber & Information Security
    • Attack Simulation
    • Office 365 & Azure Security
  • Services
    • Attack Simulation
    • Cyber & Information Security
    • Data Protection & Privacy
    • Governance, Risk and Compliance Services
    • Identity and Access Management Service
    • Office 365 & Azure Security
  • Support
    • Contact Us
    • Customer Portal
  • Company
+1 (954) 488-2643
  • Solutions
    • Governance, Risk and Compliance Services
    • Identity and Access Management Service
    • Data Protection & Privacy
    • Cyber & Information Security
    • Attack Simulation
    • Office 365 & Azure Security
  • Services
    • Attack Simulation
    • Cyber & Information Security
    • Data Protection & Privacy
    • Governance, Risk and Compliance Services
    • Identity and Access Management Service
    • Office 365 & Azure Security
  • Support
    • Contact Us
    • Customer Portal
  • Company
centristic
  • Solutions
    • Governance, Risk and Compliance Services
    • Identity and Access Management Service
    • Data Protection & Privacy
    • Cyber & Information Security
    • Attack Simulation
    • Office 365 & Azure Security
  • Services
    • Attack Simulation
    • Cyber & Information Security
    • Data Protection & Privacy
    • Governance, Risk and Compliance Services
    • Identity and Access Management Service
    • Office 365 & Azure Security
  • Support
    • Contact Us
    • Customer Portal
  • Company
Blog
Home Data Breach An Eruption of Zoom Meeting Phishing Attacks
Data BreachNEWSPhishingRansomwareTips and Tricks

An Eruption of Zoom Meeting Phishing Attacks

Roland Rodriguez Roland Rodriguez August 17, 2020 0 Comments

An eruption of Zoom-themed phishing attacks over the Spring and Summer of 2020 has been uncovered by researchers at INKY. These attacks are aimed at stealing credentials to services like Outlook and Office 365 by directing users to spoofed login pages.

The researchers say they’ve observed over the emails being sent from legitimate, compromised accounts as well as convincing spoofed domains. “At INKY, most of the Zoom impersonator phishing emails we have seen came from hijacked accounts, but we also saw newly created domain names like zoomcommuncations[.]com and zoomvideoconfrence[.]com,” they write.

INKY researchers also write, “As disturbing as that is, it’s also what makes these fake meeting invitations so easy to fall for and so difficult for traditional Secure Email Gateways (SEGs) to catch.”

Often, the attackers are using obfuscation and other techniques that make it more difficult for security systems to detect their phishing pages. “If the hacker includes a fake attachment, it leads to a fake login page that’s locally hosted on the recipient’s computer, not the internet,” the researchers write.

Often, the attackers are using obfuscation and other techniques that make it more difficult for security systems to detect their phishing pages. “If the hacker includes a fake attachment, it leads to a fake login page that’s locally hosted on the recipient’s computer, not the internet,” the researchers write.

“To make matters worse, the HTML, JavaScript, and PHP code is usually encoded so it’s unreadable to humans and automated security tools. It is a clever way to remain undetectable and evade URL reputation checkers. Similarly, if the hacker includes a malicious link, these redirect to a fake login that’s hosted on a compromised server or a hosting service the attacker paid for.”

In a number of screenshots provided by INKY, they appear identical to the legitimate login portals for Outlook and Office 365. In the Outlook example, the site’s URL was “owa-mail-auth[.]web[.]app,” which could fool even someone who had been trained to scrutinize URLs.

“They appear identical to the legitimate login portals for Outlook and Office 365.”

Attackers are constantly taking steps to improve the reach and effectiveness of their phishing campaigns. New-school security awareness training enables your employees to avoid falling for these attacks, even if the phishing sites appear perfectly convincing.

82
985 Views
Roland Rodriguez
AboutRoland Rodriguez
IT security analyst with Centristic since 2014.
In Socials:
Forget Me Not!PrevForget Me Not!August 13, 2020
Business Booming for Hackers and Cyber-Criminals: The Dark EconomyAugust 26, 2020Business Booming for Hackers and Cyber-Criminals: The Dark EconomyNext

Related Posts

Update Button on Computer Glass Keyboard
NEWSRansomwareTips and Tricks

COVID-19 vs Ransomware

The COVID-19 Pandemic is posing serious challenges to information security for firms...

Michael Blair Michael Blair June 29, 2020
Data BreachNEWSRansomwareSecurity

CISA Launches Campaign to Reduce the Risk of Ransomware – Centristic Launches Campaign to Eliminate the Risk

The Cybersecurity and Infrastructure Security Agency (CISA) announced the Reduce the...

Michael Blair Michael Blair February 2, 2021

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts
  • Cybersecurity Threat Advisory: BlackMatter Ransomware
  • CISA Launches Campaign to Reduce the Risk of Ransomware – Centristic Launches Campaign to Eliminate the Risk
  • 9 Cybersecurity Tips to Keep Your Device and Data Safe
  • Home Office Security – Never Too Late to Evaluate
  • Don’t Fall for these Holiday Scams
Subscribe to our blog
We have lots of stuff for you to read.
Categories
  • Data Breach
  • tipsEmail Scams
  • HIPAA
  • newsNEWS
  • tipsPhishing
  • phishRansomware
  • Security
  • Tips and Tricks
  • Uncategorized
Most Viewed Posts
Search our Site

Centristic delivers the industry’s most complete IT security and secured solutions to small cap business. Whatever your IT security needs and goals, and wherever you’re starting,

Quick Links
  • Solutions
  • Services
  • Support
  • Company
  • Blog
Get In Touch

Adress:
5645 Coral Ridge Dr #230 Coral Springs, FL 33076-3124
Phone:
+1 (954) 488-2643
Business Hours:
Monday – Friday: 9am to 6pm
Saturday – Sunday: Closed

Copyright © 2020 Centristic. All Rights Reserved

Close