• Skip to main content
  • Skip to site footer

Tell the Community Your Story

Submit your Fraud Alert HERE

FIND OUT HOW!
Fraud Alert

Fraud Alert

Post Your Fraud Alert Here

  • Home
  • Advice
    • Fraud Schemes
  • Add
  • Take Down
    • Take Down Requests: Honey or Vinegar – Your Choice
You are here: Home / Fraud Alerts / Phishing / Clever Phishing Trick You Need to Be Aware Of

Clever Phishing Trick You Need to Be Aware Of

01/09/2017 by Fraud Alert

Despite the ever-evolving complexity of cyber-attacks and malware code, phishing and spear-phishing attacks remain the initial entry point in many of today’s security breaches.

In most phishing attacks, crooks leverage a common theme, asking users to update their profile information on various profiles, but redirecting users to pages hosted on lookalike domains.

As users have got accustomed to this basic phishing trick in recent years, attackers found other creative ways of phishing for login credentials.

One trick, first seen in June 2016, was observed again this past month. This clever phishing attack relies on telling users they received an important or secure file, and they need to visit a web page to view it.

The real trick takes place on the crook’s page, which shows a blurred out document on the background. To view the document, users have to enter their credentials.

The blurred out document seen in the page’s background acts as a promise for what users are going to receive if they authenticate. In fact, these are nothing more than simple web pages showing an image of a blurred out document, and nothing more. The only thing working on the page is the login form that will record any login credentials that you enter inside it.

Page showing a blurred out image of a PDF file on the page’s background (Source: ISC)

Just like the 2016 attacks, crooks don’t specify which login credentials users have to fill in, and leave it to the user enter what he thinks he should entered. A careless user could enter anything from his Intranet details to Google logins.

Right now, based on the 2016 and 2017 incidents, these attacks are quite easy to detect. If the crooks behind these phishing pages would be less sloppy and spend more time in refining details, these type of attacks could be quite effective and harder to detect for what they really are.

Below are some screenshots from the June 2016 campaign.

Source: ISC

 

Share this:

  • Share on Facebook (Opens in new window) Facebook
  • Share on X (Opens in new window) X
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on WhatsApp (Opens in new window) WhatsApp

Related

Category: PhishingTag: alert, fraud, identity, passwords, phishing
  • Microsoft details the most clever phishing techniques it saw in 2019
    Date
    12/13/2019
  • Most Effective Phishing Tactic Is to Make People Think They’ve Been Hacked
    Date
    10/22/2019
  • Technology Not Training Protects Users From Phishing
    Date
    10/18/2019
  • Phishing Messages Trick One in Five Employees Into Clicking, Survey Finds
    Date
    11/08/2013
  • Phishing gets more complex as decoy PDF pops up with Microsoft-issued SSL certificate
    Date
    10/04/2018
  • Phishing Scam Leverages Fake List of Undelivered Emails to Trick Users Into Clicking
    Date
    06/10/2019
Previous Page Next Page

About Fraud Alert

Previous Post:223 Taiwanese fraud suspects held in China
Next Post:Recycled SAPS ‘Warning’ a Fraud

Copyright © Fraud Alert · Gqeberha (Port Elizabeth), South Africa | Privacy Policy