Technology Today

A new phishing campaign designed to harvest Cisco WebEx credentials through a security warning for the application has been discovered by the Cofense Phishing Defense Center (PDC).Surprisingly, Cisco's own Secure Email Gateway failed to catch this new campaign which was launched at a time when millions of people are working from home using a variety of online platforms and software.
Cybercriminals are well aware of this and have begun to exploit trusted brands like WebEx to deliver malicious emails to users.Video conferencing software has been targeted by attackers in the past but the rapid influx of remote workers during the global pandemic makes for easy prey for hackers.
Cofense anticipates that there will continue to be an increase in remote work phishing in the months to come.This latest phishing campaign begins with potential victims receiving an email with subject lines such as Critical Update or Alert from the spoofed address meetings@webex.com.
The body of the email explains that there is a vulnerability that the user must patch or risk allowing an unauthenticated user to install a Docker container with high privileges on the system.This quite clever on the part of the hackers as they have spoofed a legitimate business service and have even included links to a write-up for a legitimate vulnerability tracked as CVE-2016-9223.
To make their email more compelling, the linked article uses the same wording as the email.The attackers have also created a fake URL (https://globalpagee-prod-webex.com/signin) which, at first glance, appears quite similar to the actual Cisco WebEx URL (https://globalpage-prod.webex.com/sigin).
However, upon further inspection, it is clear that the spoofed URL contains an extra "e" and uses a dash instead of a period at the end.To carry out this attack, the hackers registered a fraudulent domain through Public Domain Registry just a few days before sending out their credential phishing email.
They even went as far as to obtain a SSL certificate for their fraudulent domain to make it appear more legitimate.
Once again though there is a discrepancy though, as the official Cisco certificate is verified by HydrantID while the attacker's certificate is through Sectigo Limited.The phishing page then redirects users to a fake Cisco WebEx login page that is visually identical to the real thing.
Once a user logs in, the attackers then have their WebEx credentials which could be sold on the dark web or used to launch additional attacks against them or their organization.Working from home certainly has its perks but remote workers must remain vigilant to avoid falling victim to this and the many other scams making their way around the internet at the moment.





Unlimited Portal Access + Monthly Magazine - 12 issues


Contribute US to Start Broadcasting - It's Voluntary!


ADVERTISE


Merchandise (Peace Series)

 


Samsung is distributing totally free Galaxy tablets worth ₤ 259 in flash summer sale


'I evaluated Hoover's cordless vacuum £& pound; 190 less expensive than Dyson I never ever knew I required'


Nintendo Switch 2 is back in stock at some UK sellers - here's how to purchase


Ryobi's cordless outdoor patio cleaner 'makes easy work' of weeds and moss 'in seconds'


Everyone with an Android phone must delete these apps now and follow 4 new rules


Everyone with an iPhone given 'important' advice - check your settings immediately


Top Tech: Best Google Pixel and Samsung deals as major Android update expected at I/O


Sky confirms exact date broadband prices will rise as 'exclusive' deals to end


Five typical home items that 'cause major WiFi' disruption


WiFi alert for UK homes with Sky, Virgin and BT broadband - check your router today


EE slashes ₤ 150 off the cost of the latest Samsung tablet, however you'll need to move fast


Sky sends important message to TV users and urges homes to follow simple advice


Argos is dishing out inexpensive iPads in extremely uncommon discount, and they are 'offering quick'


Samsung's best tablet drops to a less expensive rate and it comes with a £& pound; 339 giveaway For a


All Freeview television users given two-day warning and told to follow this new suggestions


All UK Gmail and Yahoo users placed on 'alert' and told to 'follow advice'


'Rare Apple Watch sale convinced me to upgrade my old SE device to one that's £& pound; 100 off'The Apple Watch Series 10 has been cut by £& pound; 100 at Argos, Currys, and Very, it's persuaded me to ditch my slow SE design for it.The Apple W


Tesco app down: Supermarket suffers huge outage as customers left unable to log in


Turn off your Sky TV box now - urgent alert issued to users across the UK


Top Tech: Save £400 on a Samsung Galaxy tablet with shopping expert's deal stack method


Everyone using Chrome needs to inspect their web internet browser now - don't ignore immediate alert


Sky Television down: Thousands not able to see television as service suffers big failure


Google confirms 'biggest' free Android upgrade in years and here's your first look


Sky announces surprise price alert and the exact date when it may affect you


Sky beats Samsung by handing out a £220 freebie with new S25 Edge phones


Amazon vacuum cleaner falls to record-low and branded 'exceptional for the price'


Apple fans can get an iPad for ₤ 10.50 a month as Sky releases brand-new offer


Lesser-known sale cutting cash off Ninja and Shark - however it ends this evening