Technology Today

A new phishing campaign designed to harvest Cisco WebEx credentials through a security warning for the application has been discovered by the Cofense Phishing Defense Center (PDC).Surprisingly, Cisco's own Secure Email Gateway failed to catch this new campaign which was launched at a time when millions of people are working from home using a variety of online platforms and software.

Cybercriminals are well aware of this and have begun to exploit trusted brands like WebEx to deliver malicious emails to users.Video conferencing software has been targeted by attackers in the past but the rapid influx of remote workers during the global pandemic makes for easy prey for hackers.

Cofense anticipates that there will continue to be an increase in remote work phishing in the months to come.This latest phishing campaign begins with potential victims receiving an email with subject lines such as “Critical Update” or “Alert” from the spoofed address “This email address is being protected from spambots.

You need JavaScript enabled to view it. document.getElementById('cloakb53e81dbced3880ed80260394d98d853').innerHTML = ''; var prefix = 'ma' + 'il' + 'to'; var path = 'hr' + 'ef' + '='; var addyb53e81dbced3880ed80260394d98d853 = 'meetings' + '@'; addyb53e81dbced3880ed80260394d98d853 = addyb53e81dbced3880ed80260394d98d853 + 'webex' + '.' + 'com'; var addy_textb53e81dbced3880ed80260394d98d853 = 'meetings' + '@' + 'webex' + '.' + 'com';document.getElementById('cloakb53e81dbced3880ed80260394d98d853').innerHTML += ''+addy_textb53e81dbced3880ed80260394d98d853+''; ”.

The body of the email explains that there is a vulnerability that the user must patch or risk allowing an unauthenticated user to install a “Docker container with high privileges on the system”.This quite clever on the part of the hackers as they have spoofed a legitimate business service and have even included links to a write-up for a legitimate vulnerability tracked as CVE-2016-9223.

To make their email more compelling, the linked article uses the same wording as the email.The attackers have also created a fake URL (https://globalpagee-prod-webex.com/signin) which, at first glance, appears quite similar to the actual Cisco WebEx URL (https://globalpage-prod.webex.com/sigin).

However, upon further inspection, it is clear that the spoofed URL contains an extra "e" and uses a dash instead of a period at the end.To carry out this attack, the hackers registered a fraudulent domain through Public Domain Registry just a few days before sending out their credential phishing email.

They even went as far as to obtain a SSL certificate for their fraudulent domain to make it appear more legitimate.

Once again though there is a discrepancy though, as the official Cisco certificate is verified by HydrantID while the attacker's certificate is through Sectigo Limited.The phishing page then redirects users to a fake Cisco WebEx login page that is visually identical to the real thing.

Once a user logs in, the attackers then have their WebEx credentials which could be sold on the dark web or used to launch additional attacks against them or their organization.Working from home certainly has its perks but remote workers must remain vigilant to avoid falling victim to this and the many other scams making their way around the internet at the moment.





Unlimited Portal Access + Monthly Magazine - 12 issues-Publication from Jan 2021


Buy Our Merchandise (Peace Series)

 


Contribute US to Start Broadcasting



It's Voluntary! Take care of your Family, Friends and People around You First and later think about us. Its Fine if you dont wish to contribute and if you wish to contribute then think about the Homeless first and Feed them. We can survive with your wishes too :-). You can Buy our Merchandise too which are of the finest quality.

Debit/Credit/UPI

UPI/Debit/Credit

Paytm


STRIPE


Popular Android apps are harming your phone - 5 things you must delete immediately


What jobs will AI replace? Share your views on the advanced tech


Virgin Media sends out essential text alert to all UK users - check your phone now


Sky dishes out all-new Apple iPads at prices that feel far more affordable


Samsung TV fans get 48-hour countdown to claim free Galaxy S24 - don't miss out


Google issues urgent Chrome update to all UK users - relaunch your browser today


Surprise Samsung Galaxy S24 deal lets you own this phone for less than half-price


Apple simply eliminated one of its most popular products however there's still time to purchase it


Apple launches stellar refurbished iPad deal after price cut


Windows 10 beats Windows 11 again but worrying deadline still looms for millions


Google does record your voice but there's a very simple way to stop it


WhatsApp confirms biggest change to chat app in years and it's coming to your phone soon


Netflix viewers furious following controversial subscription change


Argos and Amazon buyers hurry to get inexpensive AirPods at costs Apple won't match


Urgent WhatsApp chat cautioning issued to all UK users - ignoring it will be pricey


Blockbuster Sky television upgrade will offer you more things to watch for totally free


Check your Galaxy phone now - Samsung releases surprise free upgrade this month


Popular iPad lastly gets method more budget-friendly - Apple slashes UK tablet costs


Google's feature-packed new Android phone is way better than its low cost suggests


Apple releases biggest iPad upgrade with more power, brand-new design and even a rate cut


Never lose your keys again - Apple AirTags more affordable thanks to Amazon deal


Sky problems immediate due date to broadband users - examine your Wi-Fi router today


Old landlines will be switched off in 84 brand-new UK locations - is your postcode on the list


Latest Hisense deal will offer tech fans ? 300 if they update their television


New free TV service has launched in the UK but it can't match Sky just yet





54