Thursday, December 19, 2024
HomeComputer SecurityHackers Hiding Malware behind Captcha to Bypass Secure Email Gateways

Hackers Hiding Malware behind Captcha to Bypass Secure Email Gateways

Published on

SIEM as a Service

Hackers using Captcha to hide the presence of malware and to evade email security gateways. By using this technique attackers show that email is sent human and evades detection.

Attackers use various social engineering methods to trick the users to believe the emails is from a legitimate source, here the email’s are from a compromised account at @avis.ne.jp.

Hidden Malicious Page Behind Captcha

Cofense identified a new email campaign that alerts recipients that they received a new voicemail message. The voice was with a preview that tempts users to listen to the full message.

- Advertisement - SIEM as a Service
Email Body credits: Cofense

The email contains a play button which has an embedded hyperlink pointing to the page that contains captcha, this step is to bypass the automated analysis tools and to bypass secure email gateways.

Once the user click’s on the link they get directed to the captcha page, once the captcha check completed users taken to the main phishing page that hosted on MSFT infrastructure.

The phishing page asks the user to select a Microsoft account to log in when the victim login all their credentials are captured.

Phishing page Image credits: Cofense

“Both pages are legitimate Microsoft top-level domains, so when checking these against domain reputation databases we receive a false negative and the pages come back as safe,” reads Cofense report.

The attack method is nothing new, the important part is the Captcha page which makes the attack more successful by evading the security controls placed.

Email Header Analysis always helps you in preventing such malicious threat, emails are the critical business asset and they need to be secured.

Before clicking on a link, investigate that the website is safe, there are various methods to the check is this website safe or not.

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity and hacking news updates.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Hackers Weaponizing LNK Files To Create Scheduled Task And Deliver Malware Payload

TA397, also known as Bitter, targeted a Turkish defense organization with a spearphishing email...

BADBOX Botnet Hacked 74,000 Android Devices With Customizable Remote Codes

BADBOX is a cybercriminal operation infecting Android devices like TV boxes and smartphones with...

Europol Details on How Cyber Criminals Exploit legal businesses for their Economy

Europol has published a groundbreaking report titled "Leveraging Legitimacy: How the EU’s Most Threatening Criminal...

CISA Proposes National Cyber Incident Response Plan

The Cybersecurity and Infrastructure Security Agency (CISA) has unveiled a proposed update to the...

API Security Webinar

72 Hours to Audit-Ready API Security

APIs present a unique challenge in this landscape, as risk assessment and mitigation are often hindered by incomplete API inventories and insufficient documentation.

Join Vivek Gopalan, VP of Products at Indusface, in this insightful webinar as he unveils a practical framework for discovering, assessing, and addressing open API vulnerabilities within just 72 hours.

Discussion points

API Discovery: Techniques to identify and map your public APIs comprehensively.
Vulnerability Scanning: Best practices for API vulnerability analysis and penetration testing.
Clean Reporting: Steps to generate a clean, audit-ready vulnerability report within 72 hours.

More like this

Hackers Weaponizing LNK Files To Create Scheduled Task And Deliver Malware Payload

TA397, also known as Bitter, targeted a Turkish defense organization with a spearphishing email...

BADBOX Botnet Hacked 74,000 Android Devices With Customizable Remote Codes

BADBOX is a cybercriminal operation infecting Android devices like TV boxes and smartphones with...

New I2PRAT Malware Using encrypted peer-to-peer communication to Evade Detections

Cybersecurity experts are sounding the alarm over a new strain of malware dubbed "I2PRAT,"...