Hackers gain targets high-profile or social media influencers Instagram accounts with phishing links and gain access to the accounts before the influencers even know what’s happening.
Based on the Trend Micro’s report the hackers target the Instagram profiles that have followers between 15,000 and 70,000 were hacked and targets range from famous actors and singers to owners of startup businesses like photoshoot equipment rentals.
The attack starts with the Phishing Email that appears to be from Instagram asking the victim to verify the account to get the Verified badge on the Instagram profile.
If the victim clicks on the Verify Account button then it takes the victim to the phishing page that asks for the following user details such as date of birth, email, and credentials.
“Once submitted, a badge notification appears, but for only four seconds. This is a trick to give users the impression that their profile has been verified”, reads Trend Micro blog post. But the reality is that the hackers exfiltrate the credentials.
As the user enters the credentials in the phishing page attackers get access to the credentials and by using the stolen credentials they gain access to the Instagram profiles and modify the information that requires to recover the stolen account.
Attackers use to change the username of the stolen address to indicate it is hacked and use to change the email address, again and again, to trick victim’s with security emails asking the changes were legitimate.
Researcher spotted a specific instant in which the hacker, “threatening to delete the account or never return the stolen profile unless the victim pays a ransom or sends nude photos or videos.”
Also, a hacking forum was found that tells how to manage stolen account’s so that the owners cannot get it back with the Instagram account retrieval process.
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates also you can take the Master in Wireshark Network Analysis to keep your self-updated.
The LightSpy threat actor exploited publicly available vulnerabilities and jailbreak kits to compromise iOS devices.…
White House National Cyber Director, CEOs, Key Financial Services Companies, Congressional and Executive Branch Experts…
Cybersecurity experts have identified a new Remote Access Trojan (RAT) named PySilon. This Trojan exploits…
The notorious Konni Advanced Persistent Threat (APT) group has intensified its cyber assault on organizations…
Google has updated its Chrome browser, addressing critical vulnerabilities that posed potential risks to millions…
WrnRAT is a new malware attack that cybercriminals have deployed by using popular gambling games…