Wednesday, March 3, 2021
  • Setup menu at Appearance » Menus and assign menu to Top Bar Navigation
Advertisement
  • AI Development
    • Artificial Intelligence
    • Machine Learning
    • Neural Networks
    • Learn to Code
  • Data
    • Blockchain
    • Big Data
    • Data Science
  • IT Security
    • Internet Privacy
    • Internet Security
  • Marketing
    • Digital Marketing
    • Marketing Technology
  • Technology Companies
  • Crypto News
No Result
View All Result
NikolaNews
  • AI Development
    • Artificial Intelligence
    • Machine Learning
    • Neural Networks
    • Learn to Code
  • Data
    • Blockchain
    • Big Data
    • Data Science
  • IT Security
    • Internet Privacy
    • Internet Security
  • Marketing
    • Digital Marketing
    • Marketing Technology
  • Technology Companies
  • Crypto News
No Result
View All Result
NikolaNews
No Result
View All Result
Home Internet Security

Microsoft Office 365: This targeted phishing campaign uses an odd trick to stay hidden

October 1, 2020
in Internet Security
Microsoft Office 365: This targeted phishing campaign uses an odd trick to stay hidden
586
SHARES
3.3k
VIEWS
Share on FacebookShare on Twitter

A surge of phishing emails aimed at stealing steal corporate Microsoft Office 365 usernames and passwords is targeting a wide range of organisations and is trying to use captchas as an unusual technique to lull victims into a fall sense of security.

Captchas are usually used by online services as a means of ensuring security by requiring some sort of human input – such as checking a box or identifying particular images – to prevent automated activity by bots. In this case, cyber criminals are apparently harnessing a set of captchas to help their campaign.

You might also like

Ransomware puzzle: These two pieces of malware look very different, but they evolved from the same root

Google addresses customer data protection, security in Workspace

Australia’s new ‘hacking’ powers considered too wide-ranging and coercive by OAIC

The goal of the attack is to steal corporate Microsoft Office 365 usernames and passwords. These could be used to gain access to sensitive information, as a means of compromising the network with ransomware or even launching additional attacks against other companies that have a relationship with the victim organisation.

SEE: Security Awareness and Training policy (TechRepublic Premium)

Industries targeted by the attacks include finance, technology, manufacturing, government, pharmaceuticals, oil and gas, hospitality and more.

The campaign has been discovered and detailed by cybersecurity researchers at Menlo Security and involves phishing emails containing links that direct to a webpage posing as a Microsoft Office 365 login portal. It’s likely the attacks are customised depending on the selected target.

But rather than taking the potential victim straight to the fake page, the credential phishing site is obscured behind captchas, requiring the user to confirm they’re not a bot.

This could be an effort to make the fake log-in page look more legitimate, because people have got used to a captcha page serving as a security check.

But this isn’t the only captcha check used by the attackers, with a second stage asking the user to identify images of bicycles and a third stage asking users to identify the tiles containing a crosswalk. Only then will they be taken to the fake Office 365 login page.

SEE: This worm phishing campaign is a game-changer in password theft, account takeovers

These additional checks helps prevent automated services from reaching the phishing page and potentially identifying it as malicious – and providing the attackers with a better chance of stealing login credentials.

“The campaign is very prolific,” Vinay Pidathala, director of security research at Menlo Security told ZDNet. “With the data we have, we would classify this as a successful campaign.”

It’s uncertain what sort of operation is behind this phishing campaign, but it’s likely that it’s still active. In order to help protect against this and other phishing attacks, it’s recommended that organisations apply multi-factor authentication and that users should be wary of opening links or attachments in emails that come from an unknown source.

MORE ON CYBERSECURITY

Credit: Zdnet

Previous Post

New Android Spyware Found Posing as Telegram and Threema Apps

Next Post

How machine learning helps scientists hunt for particles, wrangle floppy proteins and speed discovery

Related Posts

Ransomware puzzle: These two pieces of malware look very different, but they evolved from the same root
Internet Security

Ransomware puzzle: These two pieces of malware look very different, but they evolved from the same root

March 3, 2021
Google addresses customer data protection, security in Workspace
Internet Security

Google addresses customer data protection, security in Workspace

March 2, 2021
Australia’s new ‘hacking’ powers considered too wide-ranging and coercive by OAIC
Internet Security

Australia’s new ‘hacking’ powers considered too wide-ranging and coercive by OAIC

March 2, 2021
Scientists have built this ultrafast laser-powered random number generator
Internet Security

Scientists have built this ultrafast laser-powered random number generator

March 2, 2021
SolarWinds security fiasco may have started with simple password blunders
Internet Security

SolarWinds security fiasco may have started with simple password blunders

March 2, 2021
Next Post
How machine learning helps scientists hunt for particles, wrangle floppy proteins and speed discovery

How machine learning helps scientists hunt for particles, wrangle floppy proteins and speed discovery

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

Plasticity in Deep Learning: Dynamic Adaptations for AI Self-Driving Cars

Plasticity in Deep Learning: Dynamic Adaptations for AI Self-Driving Cars

January 6, 2019
Microsoft, Google Use Artificial Intelligence to Fight Hackers

Microsoft, Google Use Artificial Intelligence to Fight Hackers

January 6, 2019

Categories

  • Artificial Intelligence
  • Big Data
  • Blockchain
  • Crypto News
  • Data Science
  • Digital Marketing
  • Internet Privacy
  • Internet Security
  • Learn to Code
  • Machine Learning
  • Marketing Technology
  • Neural Networks
  • Technology Companies

Don't miss it

An open-source machine learning framework to carry out systematic reviews
Machine Learning

An open-source machine learning framework to carry out systematic reviews

March 3, 2021
The Ways in Which Big Data can Transform Talent Management and Human Resources | by Amelia Jackson | Feb, 2021
Neural Networks

The Ways in Which Big Data can Transform Talent Management and Human Resources | by Amelia Jackson | Feb, 2021

March 3, 2021
Introducing Research Tuesdays: Tuesday’s daily brief
Digital Marketing

Introducing Research Tuesdays: Tuesday’s daily brief

March 3, 2021
Ransomware puzzle: These two pieces of malware look very different, but they evolved from the same root
Internet Security

Ransomware puzzle: These two pieces of malware look very different, but they evolved from the same root

March 3, 2021
Researchers Unearth Links Between SunCrypt and QNAPCrypt Ransomware
Internet Privacy

Researchers Unearth Links Between SunCrypt and QNAPCrypt Ransomware

March 3, 2021
The Effect IoT Has Had on Software Testing
Data Science

The Effect IoT Has Had on Software Testing

March 3, 2021
NikolaNews

NikolaNews.com is an online News Portal which aims to share news about blockchain, AI, Big Data, and Data Privacy and more!

What’s New Here?

  • An open-source machine learning framework to carry out systematic reviews March 3, 2021
  • The Ways in Which Big Data can Transform Talent Management and Human Resources | by Amelia Jackson | Feb, 2021 March 3, 2021
  • Introducing Research Tuesdays: Tuesday’s daily brief March 3, 2021
  • Ransomware puzzle: These two pieces of malware look very different, but they evolved from the same root March 3, 2021

Subscribe to get more!

© 2019 NikolaNews.com - Global Tech Updates

No Result
View All Result
  • AI Development
    • Artificial Intelligence
    • Machine Learning
    • Neural Networks
    • Learn to Code
  • Data
    • Blockchain
    • Big Data
    • Data Science
  • IT Security
    • Internet Privacy
    • Internet Security
  • Marketing
    • Digital Marketing
    • Marketing Technology
  • Technology Companies
  • Crypto News

© 2019 NikolaNews.com - Global Tech Updates