Skip to content
The Cyber Security Place

Expert Articles

Coronavirus Fears Spur New Phishing Attacks

Reported by mspoweruser.com

By Atif Mushtaq, Founder and CEO of SlashNext,

It was only a matter of time before hackers started exploiting global fears about the coronavirus outbreak. They started with targeted phishing attacks that rely on fake credential-stealing log-in pages to take advantage of the situation.

Savvy cybercriminals often tie their attacks to current events and trending topics that command the public’s attention, such as the Olympic Games, the Academy Awards show, or IRS tax-filing deadlines. The hackers have sensed an opening since the World Health Organization declared the rapid worldwide spread of coronavirus to be an international public health emergency.

In addition, U.S. Secretary of Health and Human Services Alex Azar has warned about the real threats for citizens in the United States. For the bad guys, such a potential worldwide pandemic is the best kind of news story because it creates an opportunity to take advantage of public fears and anxieties.

Reports have already surfaced of coronavirus-related phishing attacks popping up in the U.S., Europe, India, China and elsewhere in Asia. Email attachments and credential stealing are the two most popular phishing methods because they are simple to implement and they often evade traditional security tools, delivering higher response rates.

Our researchers have detected several credential stealing URLs related to the coronavirus epidemic. Credential stealing techniques adopt believable but phony domains to fool people into entering their logins and passwords, which the crooks then use to access private data, corporate secrets and financial accounts.

The first fake site our research found is an information and news alert page that uses a fake Microsoft login page for credential stealing, seen here:

The second credential stealing page we discovered is a fake DocuSign login site, seen below. Both login pages feature a coronavirus related domain or URL variation to trick users into having a false sense of security.

These login URLs are just a small sample of the phishing attack vectors currently springing up all over the world. Many of these threats employ coronavirus-related URL variations to deceive targets, while others replicate well known health organization sites to project authenticity. Some examples include:

A Microsoft Security Intelligence Report found that phishing attacks spiked by 250% in 2018, and they have continued to grow. Microsoft found that the bad guys often shifted to multiple points of attack during the same campaign to camouflage their actions, and they switched between URLs, domains, and servers when sending e-mails and hosting phishing forms. Microsoft also reported “an increase in the use of compromised accounts to further distribute malicious emails both inside and outside an organization.”

Clearly, such pervasive phishing attacks present a growing risk for businesses and individuals around the globe, especially when people are frightened for their personal health and well-being. The spread of coronavirus poses a scary public health threat, while also being exploited to con unsuspecting victims into making hasty decisions. We would remind people to breathe deeply and exercise caution before making the mistake of clicking on the wrong links and mistakenly giving away their personal information.

Atif Mushtaq has spent most of his career on the front lines of the war against cybercrime. Before founding SlashNext, he spent nine years as a senior scientist at FireEye where he was one of the main architects of its core malware detection system. Mushtaq has worked with law enforcement and other global agencies to take down some of the world’s biggest malware networks including Rustock, Srizbi, Pushdo and Grum botnets.

Read the full article at mspoweruser.com