Criminals use stupidly simple tactic to send malicious links - and it's working

vtqhtr413

Level 26
Thread author
Verified
Top Poster
Well-known
Aug 17, 2017
1,492
Criminals are using a remarkably straightforward tactic to try and direct victims to phishing links - but the bad news is that it appears to be working. Usually, hackers would draft this elaborate email trying to convince the victims to click on a link found at the bottom of the message. These emails would either tell the recipients they urgently needed to download an antivirus or cancel a pending transaction that will leave them broke, or something similar.

However, cybersecurity researchers from Check Point Harmony Email have uncovered that some hackers are replacing all of that with a simple image. Instead of typing out a long email and risking being found out by typos or bad grammar, these attackers simply generate a promotional image - a flyer informing the recipients they’ve won a prize or are invited to participate in a some kind of competition.
 

vtqhtr413

Level 26
Thread author
Verified
Top Poster
Well-known
Aug 17, 2017
1,492
Inky described the campaign's approach as “spray and pray” because the threat actors behind it send the emails to as many people as possible to generate results.

There are a few things that make this campaign stand out. First, the emails contain no text. Instead, they have only an attached image file. This allows the emails to escape notice by security protections that analyze the text-based words sent in an email. Some email programs and services, by default, automatically display attached images directly in the body, with some providing no way to suppress them. Recipients then often don’t notice that the image-based email contains no text.

Another distinguishing feature: the images embed a QR code that leads to the credential-harvesting site. This can reduce the time it takes to visit the site and lower the chance the employee will realize something is amiss.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top