Technology Today

A new phishing campaign designed to harvest Cisco WebEx credentials through a security warning for the application has been discovered by the Cofense Phishing Defense Center (PDC).Surprisingly, Cisco's own Secure Email Gateway failed to catch this new campaign which was launched at a time when millions of people are working from home using a variety of online platforms and software.

Cybercriminals are well aware of this and have begun to exploit trusted brands like WebEx to deliver malicious emails to users.Video conferencing software has been targeted by attackers in the past but the rapid influx of remote workers during the global pandemic makes for easy prey for hackers.

Cofense anticipates that there will continue to be an increase in remote work phishing in the months to come.This latest phishing campaign begins with potential victims receiving an email with subject lines such as “Critical Update” or “Alert” from the spoofed address “This email address is being protected from spambots.

You need JavaScript enabled to view it. document.getElementById('cloakcf5e3f9f35cfb69e98322f35d7094094').innerHTML = ''; var prefix = 'ma' + 'il' + 'to'; var path = 'hr' + 'ef' + '='; var addycf5e3f9f35cfb69e98322f35d7094094 = 'meetings' + '@'; addycf5e3f9f35cfb69e98322f35d7094094 = addycf5e3f9f35cfb69e98322f35d7094094 + 'webex' + '.' + 'com'; var addy_textcf5e3f9f35cfb69e98322f35d7094094 = 'meetings' + '@' + 'webex' + '.' + 'com';document.getElementById('cloakcf5e3f9f35cfb69e98322f35d7094094').innerHTML += ''+addy_textcf5e3f9f35cfb69e98322f35d7094094+''; ”.

The body of the email explains that there is a vulnerability that the user must patch or risk allowing an unauthenticated user to install a “Docker container with high privileges on the system”.This quite clever on the part of the hackers as they have spoofed a legitimate business service and have even included links to a write-up for a legitimate vulnerability tracked as CVE-2016-9223.

To make their email more compelling, the linked article uses the same wording as the email.The attackers have also created a fake URL (https://globalpagee-prod-webex.com/signin) which, at first glance, appears quite similar to the actual Cisco WebEx URL (https://globalpage-prod.webex.com/sigin).

However, upon further inspection, it is clear that the spoofed URL contains an extra "e" and uses a dash instead of a period at the end.To carry out this attack, the hackers registered a fraudulent domain through Public Domain Registry just a few days before sending out their credential phishing email.

They even went as far as to obtain a SSL certificate for their fraudulent domain to make it appear more legitimate.

Once again though there is a discrepancy though, as the official Cisco certificate is verified by HydrantID while the attacker's certificate is through Sectigo Limited.The phishing page then redirects users to a fake Cisco WebEx login page that is visually identical to the real thing.

Once a user logs in, the attackers then have their WebEx credentials which could be sold on the dark web or used to launch additional attacks against them or their organization.Working from home certainly has its perks but remote workers must remain vigilant to avoid falling victim to this and the many other scams making their way around the internet at the moment.





Unlimited Portal Access + Monthly Magazine - 12 issues-Publication from Jan 2021


Buy Our Merchandise (Peace Series)

 


Contribute US to Start Broadcasting



It's Voluntary! Take care of your Family, Friends and People around You First and later think about us. Its Fine if you dont wish to contribute and if you wish to contribute then think about the Homeless first and Feed them. We can survive with your wishes too :-). You can Buy our Merchandise too which are of the finest quality.

Debit/Credit/UPI

UPI/Debit/Credit

Paytm


STRIPE


Rare Apple offer drops iPad to new low rate however something better is coming soon


Scientists establish 'poisonous AI' that comes up with 'hazardous' responses to disturbing concerns


Samsung will give you a free Galaxy S24 smartphone by simply updating your TV


Check your Freeview television today or lose out on new channels and 'crucial' changes


Virgin Media concerns 48-hour countdown to claim complimentary Nintendo Switch - don't lose out


Usage Chrome on your Android phone Overlooking 'significant' brand-new danger will be costly


'I halved my cleaning time thanks to IMOU's ? 390 robot vacuum-- it even assisted get rid of family pet hair'


I attempted a Sky TV competitor that's completely free and it's pertaining to UK homes soon


Your LG TV just got a blockbuster upgrade that offers more channels for free


Motorola's Razr 40 which rivals Samsung's foldable ZFlip5 has £300 off this week


Do you think TikTok should be banned Vote in our poll and have your say


BT and Sky users must check their postcode now - huge broadband upgrade confirmed


Apple will launch something new next month - exact date and time you need to know


'Terrifying' Apple iPhone feature could save your life - but hardly anyone knows it exists


UK's 'best' broadband exposed and the result will shock you - is it time to change


TalkTalk will provide you a totally free ? 55 Echo Dot when you upgrade your broadband


Argos consumers dash to get Samsung 4K TVs at 'most affordable ever' cost - don't lose out


Forget your phone, 4K TV and earbuds - Sony will release a hot new UK gadget


Bag Motorola's brand-new budget phone with little-known offer that comes with complimentary £& pound; 129 earphones


WiFi router positioning mistake could be slowing down your internet, says specialist


UK Gmail and Yahoo users placed on email red alert - getting 'caught out' will be pricey


Your Samsung TV is about to look inferior - something new comes to the UK this week


Upgrade your TV and you'll get a Nintendo Switch or £& pound; 200 totally free, here's how to bag the offer


Microsoft employer unveils essential task interview question which is 'make or break'


Disconnect your TV, laptop computer and mobile phone tonight, cautioning issued to all UK homes


Examine your Galaxy phone now - Samsung verifies a wise totally free upgrade is coming soon


Get Fallout 3, 76 and New Vegas free with Amazon Prime Gaming offer


UK's 'worst' mobile networks verified - is your phone service provider bottom of the list





54