Recently, Microsoft has unveiled details of a deceptive social engineering campaign, in which the operators proceeded to change their obfuscation and encryption devices every 37 days on average.
The campaign also includes relying on Morse code, cover their routes, and reap secretly the credentials of users. The research team of Microsoft stated in this kind of phishing attack, the threat actors encourage the victims to assign their Office 365 credentials using XLS.HTML attachments.
Not only this but to make the campaign legitimate criminals hide the letters as statements and use different information about possible victims, like:-
However, this kind of phishing attack is quite unique in nature and the lengths attackers exert to encode the HTML file so that they can easily bypass security controls.
As previously the HTML attachments are generally divided into different segments, and all of them were encoded using different encoding mechanisms.
Moreover, this type of phishing attack’s has segments that are generally deconstructed in the following diagram:-
As we said that there is a different segment that deals with a different category, that’s why here we have mentioned them below:-
Here’s the list of all modified file extensions and variations used by the threat actors:-
However, the Microsoft Defender for Office 365 discovered the malicious emails from this phishing campaign through different, multi-layered, and cloud-based machine that has learning models and dynamic interpretation.
Not only this but the Microsoft Defender for Office 365 also has a built-in sandbox where different portfolios and URLs are exploded and tested for maliciousness like it has particular file characteristics, methods, and other behavior.
Moreover, the Microsoft Defender for Office 365 is also withdrawn by Microsoft experts that generally monitor the threat panorama for new attacker tools and methods.
The security analysts have suggested some mitigation, that is to be followed by the victims as well as the users, and that’s why here we have mentioned them below:-
The cybersecurity researchers also asserted that all the tactics and methods used by the threat actors are simply allowing them to enhance their security mechanisms against emerging security threats.
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity and hacking news updates.
Researchers observed Lumma Stealer activity across multiple online samples, including PowerShell scripts and a disguised…
Palo Alto Networks reported the Contagious Interview campaign in November 2023, a financially motivated attack…
The recent discovery of the NjRat 2.3D Professional Edition on GitHub has raised alarms in…
A critical vulnerability, CVE-2024-3393, has been identified in the DNS Security feature of Palo Alto…
Threat Analysts have reported alarming findings about the "Araneida Scanner," a malicious tool allegedly based…
A major dark web operation dedicated to circumventing KYC (Know Your Customer) procedures, which involves…