Vulnerabilities / Threats

4/26/2018
11:22 AM
50%
50%

New Phishing Attack Targets 550M Email Users Worldwide

In an attempt to steal financial data, the attack bribes users with coupons in exchange for taking an online quiz.

A new phishing campaign was discovered sending more than 550 million emails within the first quarter of 2018, according to data from Vade Secure. The threat was discovered in early January and has primarily hit users in the US, UK, France, Germany, and the Netherlands.

Victims receive emails disguised to come from popular brands and services in their home country. Attackers try to steal their banking information by offering coupons or discounts in exchange for their participation in an online quiz or contest.

Experts believe a serious criminal organization is behind this campaign, which doesn't use pirated websites as many phishing attacks do. This one appears to use leased and legitimate IP addresses, servers, and domain names, which would drive infrastructure costs up to tens of thousands of dollars. They also use tools to shorten URLs and conceal the ultimate destination.

These sophisticated techniques caused the threat to bypass many existing email security tools, researchers report. Read more details here.

Interop ITX 2018

Join Dark Reading LIVE for a two-day Cybersecurity Crash Course at Interop ITX. Learn from the industry’s most knowledgeable IT security experts. Check out the agenda here. Register with Promo Code DR200 and save $200.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
4/30/2018 | 9:24:09 PM
Re: online quiz or contest
True enough, but I have been known to search for a coupon code or two.... Anything that actively searches for you can turn into trouble.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
4/29/2018 | 6:00:11 PM
Re: Coupon lure is emblematic of broader concern
As data is shared, sold, stolen, inherited and otherwise obtained from a variety of sources and over time It becomes more valuable. Now it is noy only the raw data but also the relation, that is invaluable.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
4/29/2018 | 5:57:59 PM
Re: Coupon lure is emblematic of broader concern
The real threat from casually proffered data I woudl agree, that is the one actionable and most impactful.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
4/29/2018 | 5:55:57 PM
Re: Coupon lure is emblematic of broader concern
enterprise might invest large sums to attain data of a similar nature shouldn't surprise us. When facebook says we do not sell user data, they play with the wording, of course they sell data, that is what ads are about, they would not get any ads if they did not have the data
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
4/29/2018 | 5:53:06 PM
Re: Coupon lure is emblematic of broader concern
others value data which we don't That is true, we give ot away for free to facebook , google and otehrs without any concern what so ever.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
4/29/2018 | 5:51:38 PM
online quiz or contest
online quiz or contest are good way of gettign people engage and trapped. My rule is: I do not need any coupon or discount on anyting from the Internet.
BrianN060
50%
50%
BrianN060,
User Rank: Ninja
4/26/2018 | 1:19:38 PM
Coupon lure is emblematic of broader concern
For decades, retailers have used "with your card" coupons to generate data about their customers (who doesn't have a wallet, keychain or smartphone full of "membership cards"?).  The key takeaways with these incentives are: that others value data which we don't, and that we have come to accept these forms of coercion to participate.  That a criminal enterprise might invest large sums to attain data of a similar nature shouldn't surprise us. 

Also, the enticements to participate in social media services, such as Facebook, are of a similar nature, and serve the same purpose: to leave us little choice but to take the bait.  After all, how many can afford to pay a third more at the grocery store, or not to participate in a "Facebook only" web event? 

The data gathered, even if we are aware of the extent, never seems to be anything we should worry about - and taken as individual packets, utilized by the original entity, perhaps it isn't.  The real threat from casually proffered data is when it is processed in combination with data from a number of sources and instances.  As data is shared, sold, stolen, inherited and otherwise obtained from a variety of sources and over time, the value of this "information ore" to someone we never met far exceeds the cost of collection. 

At the end of the day, does it really matter if the organization or website used to obtain this "trivial" data is legitimate or not?  Data has no loyalty

 
Microsoft President: Governments Must Cooperate on Cybersecurity
Kelly Sheridan, Staff Editor, Dark Reading,  11/8/2018
5 Reasons Why Threat Intelligence Doesn't Work
Jonathan Zhang, CEO/Founder of WhoisXML API and TIP,  11/7/2018
Why Password Management and Security Strategies Fall Short
Steve Zurier, Freelance Writer,  11/7/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
Online Malware and Threats: A Profile of Today's Security Posture
Online Malware and Threats: A Profile of Today's Security Posture
This report offers insight on how security professionals plan to invest in cybersecurity, and how they are prioritizing their resources. Find out what your peers have planned today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-8584
PUBLISHED: 2018-11-14
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka "Windows ALPC Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows Server 2019, Windows 10 Servers.
CVE-2018-8588
PUBLISHED: 2018-11-14
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8541, CVE-2018-8...
CVE-2018-8589
PUBLISHED: 2018-11-14
An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k.sys, aka "Windows Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2.
CVE-2018-8592
PUBLISHED: 2018-11-14
An elevation of privilege vulnerability exists in Windows 10 version 1809 when installed from physical media (USB, DVD, etc, aka "Windows Elevation Of Privilege Vulnerability." This affects Windows 10, Windows Server 2019.
CVE-2018-8600
PUBLISHED: 2018-11-14
A Cross-site Scripting (XSS) vulnerability exists when Azure App Services on Azure Stack does not properly sanitize user provided input, aka "Azure App Service Cross-site Scripting Vulnerability." This affects Azure App.