Sunday, April 13, 2025
HomeCyber Security NewsSign in to Leak Your Credentials - Attackers Abusing Legitimate Services

Sign in to Leak Your Credentials – Attackers Abusing Legitimate Services

Published on

SIEM as a Service

Follow Us on Google News

An ongoing phishing campaign has found that attackers abuse legitimate credential harvesting services and data exfiltration to avoid detection.

With 59% of assaults recorded, credential harvesting has consistently been the most common attack vector.

It contributes significantly to business email compromise (BEC), which accounts for 15% of all assaults.

- Advertisement - Google News

HTML files are among the most popular attack vectors attackers use for phishing and other frauds.

More than 50% of malicious attachments are HTML files, according to Check Point’s telemetry.

Many such files pose as login pages for well-known services and companies, including Microsoft, Webmail, etc., to trick the user.

Process Of Harvesting Credentials

It has been noted that continuing efforts involving tens of thousands of emails use reputable services like EmailJS, Formbold, Formspree, and Formspark to collect these stolen credentials.

Many developers use these online form builders to design unique forms for their websites or web applications.

To help to gather user data systematically, they could include a variety of form field kinds, including text input fields, radio buttons, checkboxes, dropdown menus, and more.

After a user submits the form, the service will perform data processing and gather these compromised credentials.

Credential Harvesting Process

A type of hack known as “credential harvesting” allows criminals to get sensitive information such as usernames and passwords to gain initial company access or sell it online. 

Dark web forum selling stolen credentials

According to the report shared with Cyber Security News, attackers increasingly use legitimate services, making it more difficult to fight against and may result in credential theft.

“This new method of using a legitimate form service’s API, which many developers also use, makes malicious HTML files harder to block,” researchers explain.

“By using this API, the credentials can be sent to wherever the attacker chooses. It could even be in his mailbox”.

Phishing page using EmailJS

One of the ongoing campaigns that the Check Point Research team found begins with a phishing email that makes the recipient feel pressured to open the attachment.

The campaign used many versions of the email and several HTML templates.

The victim’s email address is already filled out in the form by the campaign author since it is hardcoded in the HTML file, giving the sign-in page a more trustworthy appearance. 

The attacker receives the victim’s login and password as soon as the victim submits his credentials and tries to log in since they are sent directly to his email inbox.

To effectively defend against phishing attempts, an organization must implement security awareness training, email filtering, scanning for malicious attachments, checking for spelling and grammar, and anti-phishing solutions.

Looking For an All-in-One Multi-OS Patch Management Platform – 

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Threat Actors Manipulate Search Results to Lure Users to Malicious Websites

Cybercriminals are increasingly exploiting search engine optimization (SEO) techniques and paid advertisements to manipulate...

Hackers Imitate Google Chrome Install Page on Google Play to Distribute Android Malware

Cybersecurity experts have unearthed an intricate cyber campaign that leverages deceptive websites posing as...

Dangling DNS Attack Allows Hackers to Take Over Organization’s Subdomain

Hackers are exploiting what's known as "Dangling DNS" records to take over corporate subdomains,...

HelloKitty Ransomware Returns, Launching Attacks on Windows, Linux, and ESXi Environments

Security researchers and cybersecurity experts have recently uncovered new variants of the notorious HelloKitty...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Threat Actors Manipulate Search Results to Lure Users to Malicious Websites

Cybercriminals are increasingly exploiting search engine optimization (SEO) techniques and paid advertisements to manipulate...

Hackers Imitate Google Chrome Install Page on Google Play to Distribute Android Malware

Cybersecurity experts have unearthed an intricate cyber campaign that leverages deceptive websites posing as...

Dangling DNS Attack Allows Hackers to Take Over Organization’s Subdomain

Hackers are exploiting what's known as "Dangling DNS" records to take over corporate subdomains,...