Cyber THREAT ADVISORY

Cyber THREAT ADVISORY

“WeTransfer” used in malicious spam campaigns"

Hackers are abusing the popular file-sharing service called “WeTransfer” to circumvent defensive email gateways that are designed to block spam messages with malicious URLs. 


What is the issue?


* Researchers have observed an uptick in attacks targeting Banking, Power and Media Industries using this technique.


* The hack abuses WeTransfer’s file sharing service, that allows any user to upload a file and share it with someone via an email link.


* To abuse this service, first a user inputs a “From” email address and a recipient email address into the “WeTransfer” interface and uploads a file. Next, the sender can customize a message that the recipient sees.


* In this campaign, the threat actor often writes a note stating that the file is an “Invoice” to be reviewed.


* When the user clicks on the “Get your files” button in the message body, the user is redirected to the “WeTransfer” download page, where the HTM or HTML file is hosted and thus, downloaded by the unsuspecting victim.


* When the user opens the “*.html” file, they are redirected to the main phishing page.


* Later, the attack continues with victims asked to enter their Office365 credentials to log in to retrieve the file.


What should you do?


* Be careful of emails containing attachments that pretend to be invoiced.


* Do not click links that look suspicious.


* To be safe, always scan the links before opening them.


* Users must check the legitimacy of the websites that they are visiting.


* When receiving emails that lead to login forms, make sure to examine the URL where the form resides before entering your login credentials.


要查看或添加评论,请登录

Shivanna Gundanavar的更多文章

  • GitLab Configuration and Upgradation

    GitLab Configuration and Upgradation

    My recent use cases of GitLab configuration and upgradation: --- GitLab Configuration and Administration: - Optimized…

  • High availability for RDS

    High availability for RDS

    To achieve high availability for a service such as RDS, you need to identify single points of failure in the…

  • VMWare Migration 5.5 to 6.5 or 6.7

    VMWare Migration 5.5 to 6.5 or 6.7

    VMware vSphere 5.5, if you haven’t upgraded already, now is the time to start your vSphere 5.

  • Migration MPX to SDX Netscaler

    Migration MPX to SDX Netscaler

    Objective This article contains information about converting NetScaler MPX appliances to NetScaler SDX appliances…

  • SDWan Implemantation on SonicWall

    SDWan Implemantation on SonicWall

    SD-WAN is an acronym for software-defined networking in a wide area network. SD-WAN simplifies the management and…

  • SharePoint and One-drive Integration and Administration

    SharePoint and One-drive Integration and Administration

    Businesses have very different approaches to data sharing among users: Some love the idea of a single portal to shared…

社区洞察

其他会员也浏览了