Sunday, July 14, 2024

Phishing Campaign Targeting Your Netflix Account ask for Login Details, Credit card and Photo ID

Phishing is one of the most common problems for Internet Users, hackers find a new innovative method to create believable URL’s to trick users. According to Google research, more than 15% accounts hijacked by using these social engineering methods. Crooks ran a Netflix phishing campaign to hijack user accounts.

Phishing campaigns run by crooks hijacking top brands and almost it is impossible to stop, With Recent Google research, they found 12.4 million potential victims of phishing kits; and 1.9 billion usernames and passwords exposed via data breaches and traded on black market forums.

Netflix Phishing Campaign

Netflix phishing campaign made a big news last week, it tricks the user to hand over login credentials, Credit card information and Photo ID.

Netflix phishing

Sophos team detailed on how this Phishing works, it starts with the Email coming from the reputed Netflix Email address with the warning that your account is “On hold”.

In the subject, attackers wrote Greek Letter Chi instead of “x”, the NETFLIX, word in the subject spelled with wired character.

The Email consist of “update now” button, on clicking it takes to a malicious site that posses like a legitimate site and asks victims to update their billing address, payment card details, Identity Info in successive steps.

Also Read Real-Time Intelligence Feed to Catch Malicious Phishing Domains SSL Certificate

To note the crooks made a convincing start that the Phishing website is HTTPS enabled with a green padlock, we should not trust HTTPS blindly and the TLS certificate is only to encrypt the connection between the browser and server.

Crooks tricked the victims with the faked Verified by VISA page to steal the payment card details, then attacks to upload your selfie to confirm your identity.

Once the crooks had all the details they redirect victims to the real Netflix login page. You can Copy the URL to analyzers that available over the Internet and ensure it’s Integrity. If it is a shortened URL you can unshorten it with the site and then analyze the actual URL.

To protect users IBM introduced a DNS security solution Quad9 that uses to protect users against most common cyber threats and their privacy.It keeps blocking you against known malicious domains and prevents your computer and IoT devices from connecting to malware or phishing sites.

Phishing and Keylogging are one of the most common problems for Internet Users, hackers keep on finding a new innovative method to create believable URL’s to trick users.


Latest articles

mSpy Data Breach: Millions of Customers’ Data Exposed

mSpy, a widely used phone spyware application, has suffered a significant data breach, exposing...

Advance Auto Parts Cyber Attack: Over 2 Million Users Data Exposed

RALEIGH, NC—Advance Stores Company, Incorporated, a prominent commercial entity in the automotive industry, has...

Hackers Using ClickFix Social Engineering Tactics to Deploy Malware

Cybersecurity researchers at McAfee Labs have uncovered a sophisticated new method of malware delivery,...

Coyote Banking Trojan Attacking Windows Users To Steal Login Details

Hackers use Banking Trojans to steal sensitive financial information. These Trojans can also intercept...

Hackers Created 700+ Fake Domains to Sell Olympic Games Tickets

As the world eagerly anticipates the Olympic Games Paris 2024, a cybersecurity threat has...

Japanese Space Agency Spotted zero-day via Microsoft 365 Services

The Japan Aerospace Exploration Agency (JAXA) has revealed details of a cybersecurity incident that...

Top 10 Active Directory Management Tools – 2024

Active Directory Management Tools are essential for IT administrators to manage and secure Active...
Guru baran
Guru baran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Free Webinar

Low Rate DDoS Attack

9 of 10 sites on the AppTrana network have faced a DDoS attack in the last 30 days.
Some DDoS attacks could readily be blocked by rate-limiting, IP reputation checks and other basic mitigation methods.
More than 50% of the DDoS attacks are employing botnets to send slow DDoS attacks where millions of IPs are being employed to send one or two requests per minute..
Key takeaways include:

  • The mechanics of a low-DDoS attack
  • Fundamentals of behavioural AI and rate-limiting
  • Surgical mitigation actions to minimize false positives
  • Role of managed services in DDoS monitoring

Related Articles