Phishing attacks via ‘URL rewriting’ to evade detection escalate – Go Health Pro

Phishing attacks via ‘URL rewriting’ to evade detection escalate – Go Health Pro

Email attackers are increasingly exploiting “URL rewriting” in phishing attacks to evade detection while spreading malicious links, Perception Point researchers said in a blog post. URL rewriting is a security measure in which an email protection service such as a Secure Email Gateway (SEG) wraps any URLs contained in a received email with new links … Read more

Microsoft Visio Phishing Attack | Be Vigilant | Neuways – Go Health Pro

Microsoft Visio Phishing Attack | Be Vigilant | Neuways – Go Health Pro

Be Vigilant – Microsoft Visio Files are now a tool in Advanced Phishing Attacks A recent surge in sophisticated phishing tactics using Microsoft Visio files (.vsdx format) has been flagged by cyber security experts as a concerning development in the ongoing battle against digital threats, which has only heightened the requirement for companies to be … Read more

AWS breaks up massive Russian phishing operation – Go Health Pro

AWS breaks up massive Russian phishing operation – Go Health Pro

Online retail giant and cloud-service provider Amazon broke up a phishing operation that impersonated thousands of Amazon Web Service (AWS) domains. The AWS security team, along with the Ukrainian CERT-UA blamed the Russian-backed APT 29 group for an attack which used spoofed AWS domains in an attempt to harvest login credentials from Ukrainian-speaking targets. Since … Read more

Gophish Framework Used in Phishing Campaigns to Deploy Remote Access Trojans – Go Health Pro

Gophish Framework Used in Phishing Campaigns to Deploy Remote Access Trojans – Go Health Pro

Russian-speaking users have become the target of a new phishing campaign that leverages an open-source phishing toolkit called Gophish to deliver DarkCrystal RAT (aka DCRat) and a previously undocumented remote access trojan dubbed PowerRAT. “The campaign involves modular infection chains that are either Maldoc or HTML-based infections and require the victim’s intervention to trigger the … Read more

GitHub, Telegram Bots, and ASCII QR Codes Abused in New Wave of Phishing Attacks – Go Health Pro

GitHub, Telegram Bots, and ASCII QR Codes Abused in New Wave of Phishing Attacks – Go Health Pro

A new tax-themed malware campaign targeting insurance and finance sectors has been observed leveraging GitHub links in phishing email messages as a way to bypass security measures and deliver Remcos RAT, indicating that the method is gaining traction among threat actors. “In this campaign, legitimate repositories such as the open-source tax filing software, UsTaxes, HMRC, … Read more

x