Saturday, January 18, 2025
HomeComputer SecurityPhishing Campaigns Targeting Google and Yahoo Accounts To Bypassing Two-Factor Authentication

Phishing Campaigns Targeting Google and Yahoo Accounts To Bypassing Two-Factor Authentication

Published on

SIEM as a Service

Follow Us on Google News

Several phishing campaigns targeting hundreds of individuals across the Middle East and North Africa. The attacker targers HRDs, journalists, political actors.

Amnesty International published a report on multiple campaigns that traget self-described “secure email” services, such as Tutanota and ProtonMail and another campaign that aimed in bypassing two-factor authentication.

Crafted Phishing Sites – Secure Email Providers

The phishing campaign primarily targeted popular secure email service providers such as Tutanota and ProtonMail.

Threat actors used a well-crafted phishing page – by obtaining the domain tutanota[.]org, whereas the original domain of the service provider is tutanota[.]com.

A phishing attack is one of the dangerous social engineering attacks that leads to capture a victim’s username and password that will get store it to an attacker machine and reuse it later.

Also, Amnesty observed that attackers registered a phishing site protonemail[.]ch that crafted like as an original valid website protonmail[.]ch. When user enters the login credentials in the fake pages, attackers steal the credentials.

Google and Yahoo – Phishing Campaigns

The targeted phishing campaign designed to bypass the two-factor authentication and the campaign likely to be from the same attacker.

Attackers used a crafted phishing Email that appeared to be from an invite to edit documents on Google Drive or an invitation for calls in Google Hangout.

“In this case, we have observed less sophisticated social engineering tricks. Most often this attacker made use of the common “security alert” scheme, which involves falsely alarming the targets with some fake notification of a potential account compromise, reads Amnesty report

The phishing pages includes a link that redirects to a well-crafted and convincing Google phishing website that designed for making victims to reveal their two-step authentication code.

Once the victim logged with in the phishing page then they will redirected to another page that sent a 2-Step Verification code, once victims presented the 2-Step Verification code then it will present a form asking us to reset the password for our account.

After that Amnesty spotted a password change was in fact issued by Windows computer operated by the attackers, seemingly connecting from an IP address that Google geolocates within the USA.

The same with Yahoo account also who configured two-factor authentication using the phone number.

How to stay safe

  1. Have a unique Email address.
  2. Do not open any attachments without proper validation.
  3. Don’t open emails voluntary emails.
  4. Use Spam filters & Antispam gateways.
  5. Never respond to any spam emails.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

ReelPhish – A Real-Time Advanced Two-Factor Authentication Phishing Tool

Real-Time Intelligence Feed to Catch Malicious Phishing Domains SSL Certificate

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Hackers Easily Bypass Active Directory Group Policy to Allow Vulnerable NTLMv1 Auth Protocol

Researchers have discovered a critical flaw in Active Directory’s NTLMv1 mitigation strategy, where misconfigured...

AWS Warns of Multiple Vulnerabilities in Amazon WorkSpaces, Amazon AppStream 2.0, & Amazon DCV

Amazon Web Services (AWS) has issued a critical security advisory highlighting vulnerabilities in specific...

FlowerStorm PaaS Platform Attacking Microsoft Users With Fake Login Pages

Rockstar2FA is a PaaS kit that mimics the legitimate credential-request behavior of cloud/SaaS platforms....

New Tool Unveiled to Scan Hacking Content on Telegram

A Russian software developer, aided by the National Technology Initiative, has introduced a groundbreaking...

API Security Webinar

Free Webinar - DevSecOps Hacks

By embedding security into your CI/CD workflows, you can shift left, streamline your DevSecOps processes, and release secure applications faster—all while saving time and resources.

In this webinar, join Phani Deepak Akella ( VP of Marketing ) and Karthik Krishnamoorthy (CTO), Indusface as they explores best practices for integrating application security into your CI/CD workflows using tools like Jenkins and Jira.

Discussion points

Automate security scans as part of the CI/CD pipeline.
Get real-time, actionable insights into vulnerabilities.
Prioritize and track fixes directly in Jira, enhancing collaboration.
Reduce risks and costs by addressing vulnerabilities pre-production.

More like this

Hackers Easily Bypass Active Directory Group Policy to Allow Vulnerable NTLMv1 Auth Protocol

Researchers have discovered a critical flaw in Active Directory’s NTLMv1 mitigation strategy, where misconfigured...

AWS Warns of Multiple Vulnerabilities in Amazon WorkSpaces, Amazon AppStream 2.0, & Amazon DCV

Amazon Web Services (AWS) has issued a critical security advisory highlighting vulnerabilities in specific...

FlowerStorm PaaS Platform Attacking Microsoft Users With Fake Login Pages

Rockstar2FA is a PaaS kit that mimics the legitimate credential-request behavior of cloud/SaaS platforms....