Wednesday, June 7, 2023
LetsAskBinu.com
  • Home
  • Cybersecurity
  • Cyber Threats
  • Hacking
  • Protection
  • Networking
  • Malware
  • Fintech
  • Internet Of Things
No Result
View All Result
LetsAskBinu.com
No Result
View All Result
Home Cybersecurity

BEC attacks emulate legitimate web services to lure clicks

Researcher by Researcher
May 20, 2023
in Cybersecurity
0
BECs Double In 2022, Overtaking Ransomware
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter


New BEC cyberattacks use phishing with a legitimate Dropbox link as a lure for malware and credentials theft.

This illustration shows a lock, unlocked over a person at a keyboard.
Image: Adobe Stock.

Threat actors have added a new wrinkle to traditional business email compromise cyberattacks. Call it BEC 3.0 — phishing attacks that bury the hook in legitimate web services like Dropbox.

Avanan, a unit of Check Point Software, has tracked a recent example of this attack family, in which hackers created free Dropbox accounts to grab credentials or hide malware in legitimate-looking, contextually relevant documents such as potential employees’ resumes.

Related articles

Ransomware, DDoS see major upsurge led by upstart hacker group

DDoS attacks dominate and pretexting lead to BEC growth

June 7, 2023
CISA: North Korea-Backed Actors Using Maui Ransomware

North Korean Attackers Target Google Account Credentials

June 7, 2023

The attack, the security firm discovered, started with the actors sharing a PDF of someone’s resume via Dropbox. The target can’t view the document unless they Add To Dropbox. The link from Dropbox looked legitimate, making the exploit more difficult to spot.

The phishing exploit involves these steps:

  • First, a user clicks the link in a legitimate notification from Dropbox to a resume and accesses a page hosted on the file-sharing service.
  • The user must then enter their email account and password to view the document. This means that the threat actors have access to email addresses and passwords.

On this page hosted on Dropbox, users are asked to enter their email account and password to view the document, giving threat actors user credentials.

Once a user enters their credentials, they are directed to a fake Microsoft OneDrive link. By clicking on the link, users are given a malicious download.

“We’ve seen hackers do a lot of BEC attacks,” Jeremy Fuchs, a cybersecurity researcher/analyst at Avanan, said in a report on the attack. “These attacks have several variations, but generally they try to spoof an executive or partner to get an end user to do something they don’t want to do (like pay an invoice to the wrong place),” he said.

SEE: Another hide-the-malware attack focuses on DNS (TechRepublic)

“Leveraging legitimate websites to host malicious content is a surefire way to get into the inbox,” he said. “Most security services will look at the sender — in this case, Dropbox — and see that it’s legitimate and accept the message. That’s because it is legitimate,” he added.

Avanan said preventing these stealth attacks requires a number of defensive steps, including scanning for malicious files in Dropbox and links in documents, as well as replacing links in the email body and inside attachments. The key to education against these social engineering attacks is context, according to Fuchs: “Are resumes typically sent via Dropbox? If not, it may be a reason to contact the original sender and double-check. If they are, take it one step further. When you log into Dropbox, do I have to log in again with my email?”

Avanan said the researchers reached out to Dropbox on May 15 to inform them of this attack and research.

Linktree also used to grab credentials

Earlier this month, Avanan discovered a similar hack using the social media reference landing page Linktree, which is hosted on sites like Instagram and TikTok. Similar to the Dropbox attacks, hackers created legitimate Linktree pages to host malicious URLs to harvest credentials.

The attackers sent targets spoofed Microsoft OneDrive or SharePoint notifications that a file has been shared with them, instructing them to open the file, according to Avanan. Ultimately, the user is redirected to a fake Office 365 login page, where they are asked to enter their credentials, where their credentials are stolen.

“[Users] should think: Why would this person send me a document via Linktree? Most likely, that wouldn’t be the case. That’s all a part of security awareness — understanding if an email or process seems logical,” said Fuchs.

In these cases, the firm suggests that recipients:

  • Always check the sender’s address before replying to an email.
  • Stop and think if the medium being used to deliver a file is typical.
  • When logging into a page, double-check the URL to see if it’s Microsoft or another legitimate site.

BEC attacks using legitimate sites may escalate this year

Fuchs said there are no obvious visual cues to tip off attack recipients to BEC exploits. “Although if you were to sign into the Dropbox page, you’d see that there’s a OneDrive logo and link,” he said. “Eagle-eyed users should notice that discrepancy and think—why would there be two competing services on one page?,” he added.

He predicted that these attacks will escalate. “Any popular service that’s legit can potentially be used as a vehicle to deliver this type of malicious activity. That’s why we expect it to take off in the near future,” he said, adding that the exploit has been used tens of thousands of times. “We believe this will really take off in volume in the second half of the year,” he said.



Source link

Tags: AttacksBECclicksemulatelegitimatelureservicesweb
Share76Tweet47

Related Posts

Ransomware, DDoS see major upsurge led by upstart hacker group

DDoS attacks dominate and pretexting lead to BEC growth

June 7, 2023
0

In Verizon’s just-released 2023 Data Breach Investigations Report, money is king, and denial of service and social engineering still hold...

CISA: North Korea-Backed Actors Using Maui Ransomware

North Korean Attackers Target Google Account Credentials

June 7, 2023
0

North Korean threat group Kimsuky has recently launched a social engineering campaign against a number of experts specializing in North...

Sentra Raises $30 Million for DSPM Technology

KeePass Update Patches Vulnerability Exposing Master Password

June 6, 2023
0

Open source password manager KeePass was updated over the weekend to patch a vulnerability allowing attackers to retrieve the cleartext...

Zero-day MOVEit Transfer vulnerability exploited in the wild

Zero-day MOVEit Transfer vulnerability exploited in the wild

June 6, 2023
0

Shodan search engine results for internet-facing MOVEit instances. Image: Shodan The Cybersecurity & Infrastructure Security Agency has issued an alert...

New DDoS Attack Vector Abuses Content Filtering Systems

UNC4857 Exploits MOVEit Transfer Flaw in Data Extortion Attacks

June 6, 2023
0

A newly discovered threat campaign has been observed exploiting the recently uncovered, critical-severity MOVEit Transfer vulnerability in order to launch...

Load More
  • Trending
  • Comments
  • Latest
This Week in Fintech: TFT Bi-Weekly News Roundup 08/02

This Week in Fintech: TFT Bi-Weekly News Roundup 15/03

March 15, 2022
QNAP Escalation Vulnerability Let Attackers Gain Administrator Privileges

QNAP Escalation Vulnerability Let Attackers Gain Administrator Privileges

March 15, 2022
Supply chain efficiency starts with securing port operations

Supply chain efficiency starts with securing port operations

March 15, 2022
A first look at threat intelligence and threat hunting tools

A first look at threat intelligence and threat hunting tools

March 15, 2022
Beware! Facebook accounts being hijacked via Messenger prize phishing chats

Beware! Facebook accounts being hijacked via Messenger prize phishing chats

0
Shoulder surfing: Watch out for eagle‑eyed snoopers peeking at your phone

Shoulder surfing: Watch out for eagle‑eyed snoopers peeking at your phone

0
Remote work causing security issues for system and IT administrators

Remote work causing security issues for system and IT administrators

0
Elementor WordPress plugin has a gaping security hole – update now – Naked Security

Elementor WordPress plugin has a gaping security hole – update now – Naked Security

0
Apple launches Vision Pro & more new products

Apple launches Vision Pro & more new products

June 7, 2023
Ransomware, DDoS see major upsurge led by upstart hacker group

DDoS attacks dominate and pretexting lead to BEC growth

June 7, 2023
Money20/20 Europe 2023: Day One TFT Roundup

Money20/20 Europe 2023: Day One TFT Roundup

June 7, 2023
Release date, price and more

Release date, price and more

June 7, 2023

Recent Posts

Apple launches Vision Pro & more new products

Apple launches Vision Pro & more new products

June 7, 2023
Ransomware, DDoS see major upsurge led by upstart hacker group

DDoS attacks dominate and pretexting lead to BEC growth

June 7, 2023
Money20/20 Europe 2023: Day One TFT Roundup

Money20/20 Europe 2023: Day One TFT Roundup

June 7, 2023

Categories

  • Cyber Threats
  • Cybersecurity
  • Fintech
  • Hacking
  • Internet Of Things
  • LetsAskBinuBlogs
  • Malware
  • Networking
  • Protection

Tags

Access attack Attacks banking BiWeekly bug Cisco cloud code critical Cybersecurity Data Digital exploited financial Fintech Flaw flaws Google Group Hackers Krebs Latest launches malware Microsoft million Network News open patches Payments platform Ransomware RoundUp security Software Stories TFT Threat Top vulnerabilities vulnerability warns Week

© 2022 Lets Ask Binu All Rights Reserved

No Result
View All Result
  • Home
  • Cybersecurity
  • Cyber Threats
  • Hacking
  • Protection
  • Networking
  • Malware
  • Fintech
  • Internet Of Things

© 2022 Lets Ask Binu All Rights Reserved