Technology Today

A new phishing campaign designed to harvest Cisco WebEx credentials through a security warning for the application has been discovered by the Cofense Phishing Defense Center (PDC).Surprisingly, Cisco's own Secure Email Gateway failed to catch this new campaign which was launched at a time when millions of people are working from home using a variety of online platforms and software.

Cybercriminals are well aware of this and have begun to exploit trusted brands like WebEx to deliver malicious emails to users.Video conferencing software has been targeted by attackers in the past but the rapid influx of remote workers during the global pandemic makes for easy prey for hackers.

Cofense anticipates that there will continue to be an increase in remote work phishing in the months to come.This latest phishing campaign begins with potential victims receiving an email with subject lines such as “Critical Update” or “Alert” from the spoofed address “This email address is being protected from spambots.

You need JavaScript enabled to view it. document.getElementById('cloaka29f02bb4f1734f2eb9c27ad7cfbb194').innerHTML = ''; var prefix = 'ma' + 'il' + 'to'; var path = 'hr' + 'ef' + '='; var addya29f02bb4f1734f2eb9c27ad7cfbb194 = 'meetings' + '@'; addya29f02bb4f1734f2eb9c27ad7cfbb194 = addya29f02bb4f1734f2eb9c27ad7cfbb194 + 'webex' + '.' + 'com'; var addy_texta29f02bb4f1734f2eb9c27ad7cfbb194 = 'meetings' + '@' + 'webex' + '.' + 'com';document.getElementById('cloaka29f02bb4f1734f2eb9c27ad7cfbb194').innerHTML += ''+addy_texta29f02bb4f1734f2eb9c27ad7cfbb194+''; ”.

The body of the email explains that there is a vulnerability that the user must patch or risk allowing an unauthenticated user to install a “Docker container with high privileges on the system”.This quite clever on the part of the hackers as they have spoofed a legitimate business service and have even included links to a write-up for a legitimate vulnerability tracked as CVE-2016-9223.

To make their email more compelling, the linked article uses the same wording as the email.The attackers have also created a fake URL (https://globalpagee-prod-webex.com/signin) which, at first glance, appears quite similar to the actual Cisco WebEx URL (https://globalpage-prod.webex.com/sigin).

However, upon further inspection, it is clear that the spoofed URL contains an extra "e" and uses a dash instead of a period at the end.To carry out this attack, the hackers registered a fraudulent domain through Public Domain Registry just a few days before sending out their credential phishing email.

They even went as far as to obtain a SSL certificate for their fraudulent domain to make it appear more legitimate.

Once again though there is a discrepancy though, as the official Cisco certificate is verified by HydrantID while the attacker's certificate is through Sectigo Limited.The phishing page then redirects users to a fake Cisco WebEx login page that is visually identical to the real thing.

Once a user logs in, the attackers then have their WebEx credentials which could be sold on the dark web or used to launch additional attacks against them or their organization.Working from home certainly has its perks but remote workers must remain vigilant to avoid falling victim to this and the many other scams making their way around the internet at the moment.





Unlimited Portal Access + Monthly Magazine - 12 issues-Publication from Jan 2021


Buy Our Merchandise (Peace Series)

 


Contribute US to Start Broadcasting



It's Voluntary! Take care of your Family, Friends and People around You First and later think about us. Its Fine if you dont wish to contribute and if you wish to contribute then think about the Homeless first and Feed them. We can survive with your wishes too :-). You can Buy our Merchandise too which are of the finest quality.

Debit/Credit/UPI

UPI/Debit/Credit

Paytm


STRIPE




SCAN and Contribute
        


The £& pound; 16 travel charging essential that holidaymakers are calling a 'life saver'


Unmissable Samsung Galaxy S24 price as John Lewis cuts ?300 off in huge offer


Surprise Samsung code offers much cheaper way to get the ultimate TV upgrade


Microsoft takes goal at Apple's MacBook with launch of its most effective ever laptop


Free UK broadband boost could also help BT, Sky and Virgin users get lower bills


Individuals fuming as Disney+ 'pulls a Netflix' with bothersome subscription crackdown


Gmail and Yahoo users must 'watch out' - ignoring new email alert will be costly


Your Windows PC might lastly measure up to the MacBook thanks to most significant modification in years


Huge complimentary Android upgrade is readily available on these phones - check your device now


Gmail is getting a very smart free upgrade and it's coming to your devices soon


Relaunch your Chrome internet browser again - don't ignore new urgent caution from Google


'Stranger has actually been utilizing my e-mail address for 5 years - I got the last laugh'


Fire TV and laptop warning - stream Fury v Usyk free of charge and face 'major risk'


Brits spot 'Black Mirror' creature crossing city street as they brand it 'drone on legs'


Millions of UK Netflix users face brand-new material block - check if you are impacted


Fortnite, WhatsApp, imessage and Facetime down: Livid users fume as apps and servers crash


EE includes Google's most recent Pixel 8a phone to its stock, here's why its cost is one to opt for


Let Dyson have your old vacuum and you'll get money off something way better


Apple verifies essential upgrades are coming to the iPhone and iPads this year


Three Mobile will give you free unlimited 5G data but there's a deal that's even better


Argos buyers are getting Samsung TVs at 'most affordable ever' rate which's not all


Your Android phone is getting among the most important complimentary upgrades in years


Popular Android apps are harming your phone - 5 things you must delete immediately


What jobs will AI replace Share your views on the advanced tech


Virgin Media sends out essential text alert to all UK users - check your phone now





54