Top Email Protections Fail in Latest COVID-19 Phishing Campaign

Top Email Protections Fail in Latest COVID-19 Phishing Campaign
Share It On:

03 April 2020 Kathmandu

An effective spoofing campaign claims to inform users about new COVID-19 cases in their local area, scooting past Proofpoint and Microsoft Office 365 ATPs.

Threats are still steady, if not growing, amid the COVID-19 pandemic. Cybercriminals continue to capitalize on fears surrounding the coronavirus outbreak. The most recent one is the effective bypassing Proofpoint and Microsoft 365 Advanced Threat Protections (ATPs).

In fact, these two tools are popular among users as top email protection. However, attackers found a way to get past the security to lure users into their phishing campaign.

The Cofense Phishing Defense Center (PDC) discovered the new phishing campaign that uses socially engineered emails claiming access to important information on COVID-19 cases in the receiver’s local area.

Phishing Campaign 101

According to the researchers, the emails evade basic security checks and use logic to bypass detection. As a result, the attackers manage to steal user’s Microsoft credentials.

Regardless of enabling the secure email gateways designed for safeguarding users from clicking on malicious links and attachments, it still failed in this new phishing attack.

According to Cofense, these emails don’t include specific names or greetings in the body of the messages. This suggests that they are being sent out to a broad target audience.

While these secure email gateways (SEGs) are designed to safeguard end users from clicking on malicious links and attachments, both failed in a new phishing attack we recently observed,” Cofense researcher Kian Mahdavi wrote in a post.

How This Phishing Campaign Works

To avoid detection by ATPs, the threat actor impersonates the domain splashmath[.]com – which is an online learning game for children. For this, it uses a spoofed IP address located in the United States, 167[.]89[.]87[.]104.

After further investigation, researchers found that the emails that were sent to a number of people didn’t come from the spoofed address. In fact, they came from an IP corresponding with the Lithuanian city of Kaunas.

This made the researchers believe that a single individual was behind the campaign.

“[Because of the proxy], the email slipped past basic security checks, such as DKIM and SPF,” Mahdavi wrote.

According to the research, the attackers are not just impersonating trusted sender’s email. Moreover, they are using keywords in the subject to trick the targeted victim into believing that the information is from a trusted source regarding COVID-19.

For instance, the words “WHO” and “community” in the email address (who[.]int-community[.]spread@ splashmath[.]com) aim to trick the user into believing that the mail is from the World Health Organization (WHO).

Similarly, the subject of the email – “HIGH-RISK: New confirmed cases in your city” – does the job of fooling users into thinking that it is an important and legitimate email.

Malicious Links Evade Detection

Cofense observed some malicious links used in the campaigns which include:

  • hXXps://heinrichgrp[.]com/who/files/af1fd55c21fdb935bd71ead7acc353d7[.]php
  • hXXps://coronasdeflores[.]cl/who
  • hXXps://www[.]frufc[.]net/who/files/61fe6624ec1fcc7cac629546fc9f25c3[.]php
  • hXXps://pharmadrugdirect[.]com/who
  • hXXps://ee-cop[.]co[.]uk/who/files/3b9f575dac9cc432873f6165c9bed507[.]php

Additionally, these links display a high-quality, spoofed Microsoft login page when users click on them. This way, they are highly misleading to users.

Once the users enter their Microsoft credentials on the login page, they get into the hands of the threat actor.

This is not the first time attackers have used the keywords related to the Coronavirus to lure users to click on malicious links. In this phishing attack, users are directed to a Microsoft branded credential phish to steal their credentials.

Read Also: Android Users At High Risk During Coronavirus Outbreak


Share It On:

Recent Posts

Kumari Bank Promoter Share Sale: Eligibility, Application Process, and Price

Kumari Bank Promoter Share Sale: Eligibility, Application Process, and Price

Share It On:21st November, Kathmandu Kumari Bank Limited has officially declared its intention to sell a substantial number of promoter

Up to NPR 150 Cashback on Nepal Telecom and Ncell Services with Namaste Pay

Up to NPR 150 Cashback on Nepal Telecom and Ncell

Share It On:21st November, Kathmandu Namaste Pay has unveiled an exciting new campaign to reward its users with cashback on

Ncell introduces innovative feature, enabling customers to convert voice to data or data to voice services

Ncell introduces innovative feature, enabling customers to convert voice to

Share It On:21st November, Kathmandu Ncell customers can enjoy an innovative feature that allows them to convert or exchange remaining

Genese Solution’s G-TEC: Empowering Women in Tech and Creating a Diverse Tech Workforce in Nepal

Genese Solution’s G-TEC: Empowering Women in Tech and Creating a

Share It On:21st November 2024, Kathmandu Genese Solution – a value IT consulting company, and Kageshwori Manohara municipality, have joined

Shikhar Insurance: Celebrating 20 Years of Service and Commitment to Nepali Customers

Shikhar Insurance: Celebrating 20 Years of Service and Commitment to

Share It On:21st November 2024, Kathmandu Shikhar Insurance had a grand celebration for their 20th Anniversary. On the occasion of

India’s Generative AI Startups: A Comprehensive Look at 2024’s Key Trends and Investments

India’s Generative AI Startups: A Comprehensive Look at 2024’s Key

Share It On:21st November 2024, Kathmandu As 2024 draws to a close, India’s generative AI ecosystem stands out as a