Technology Today

A new phishing campaign designed to harvest Cisco WebEx credentials through a security warning for the application has been discovered by the Cofense Phishing Defense Center (PDC).Surprisingly, Cisco's own Secure Email Gateway failed to catch this new campaign which was launched at a time when millions of people are working from home using a variety of online platforms and software.
Cybercriminals are well aware of this and have begun to exploit trusted brands like WebEx to deliver malicious emails to users.Video conferencing software has been targeted by attackers in the past but the rapid influx of remote workers during the global pandemic makes for easy prey for hackers.
Cofense anticipates that there will continue to be an increase in remote work phishing in the months to come.This latest phishing campaign begins with potential victims receiving an email with subject lines such as Critical Update or Alert from the spoofed address [email protected].
The body of the email explains that there is a vulnerability that the user must patch or risk allowing an unauthenticated user to install a Docker container with high privileges on the system.This quite clever on the part of the hackers as they have spoofed a legitimate business service and have even included links to a write-up for a legitimate vulnerability tracked as CVE-2016-9223.
To make their email more compelling, the linked article uses the same wording as the email.The attackers have also created a fake URL (https://globalpagee-prod-webex.com/signin) which, at first glance, appears quite similar to the actual Cisco WebEx URL (https://globalpage-prod.webex.com/sigin).
However, upon further inspection, it is clear that the spoofed URL contains an extra "e" and uses a dash instead of a period at the end.To carry out this attack, the hackers registered a fraudulent domain through Public Domain Registry just a few days before sending out their credential phishing email.
They even went as far as to obtain a SSL certificate for their fraudulent domain to make it appear more legitimate.
Once again though there is a discrepancy though, as the official Cisco certificate is verified by HydrantID while the attacker's certificate is through Sectigo Limited.The phishing page then redirects users to a fake Cisco WebEx login page that is visually identical to the real thing.
Once a user logs in, the attackers then have their WebEx credentials which could be sold on the dark web or used to launch additional attacks against them or their organization.Working from home certainly has its perks but remote workers must remain vigilant to avoid falling victim to this and the many other scams making their way around the internet at the moment.





Unlimited Portal Access + Monthly Magazine - 12 issues


Contribute US to Start Broadcasting - It's Voluntary!


ADVERTISE


Merchandise (Peace Series)

 


Fitness fans can conserve big as Amazon cuts the rate of Google Fitbit Charge 6 by 29%


Enjoy £& pound; 1.91 pints at home with £& pound; 100 off' pub-quality' draught beer taps


Countless Sky TV users lose out on 'interesting' totally free upgrade, examine your account now


Shark's 'game-changing' £100 SmoothStyle hair tool now £49 in Amazon sale


Google down RECAP: Gmail, Drive and Workspace users hit by huge outage


Virgin Media's Sky Sports bundles cut by £330 ahead of Premier League season


'I'm a TV writer and found a way to get Netflix and Sky TV for 50p per day'


'Amazing' Shark SmoothStyle hot brush on sale for under £& pound; 70 that 'dries hair quickly'


Leading Tech: Google sets Pixel 10 launch date as Pixel 9 is up to brand-new low cost


Three Mobile competitors EE, O2 and Sky with a less expensive Unlimited Data SIM-only strategy


Fitbit down: Major outage reported as numerous users grumble


'I ditched my aerial for a Freely TV and I don't regret it one bit'


Argos consumers race to grab the iPhone at 'lowest ever' cost and that's not all


Everyone using Gmail given new inbox warning - watch out for dangerous hidden message


Forget Ring - this Blink doorbell alternative is only £28.99


Leading 20 pieces of tech Brits miss the most - consisting of corded phones and movie video cameras


Everyone utilizing Chrome put on red alert and informed to clear browsing data immediately


Rare deal that rivals Amazon sale sees Samsung Galaxy Smartwatch plummet to £39


Get a free Samsung Galaxy Watch - tech editor shares where to discover it


Fortnite down RECAP: Epic Games release declaration as video game continues to be offline


Top Tech: Sky launches UK's 'fastest broadband' with big 5Gbps fibre upgrade


Virgin Media users alerted they deal with new streaming block - examine your television and act now


All UK WhatsApp users put on alert and provided with immediate pointer this week


Gtech's 'perfect' cordless vacuum package is £& pound; 200 off and makes cleaning 'a lot simpler'


TOWIE's Pete Wicks succumbs to 'fake' Wimbledon influencer who tricked him


Sky summertime sale cuts cost of family essentials but Virgin has something much better


UK Fire television Stick users will be obstructed from popular streaming app on this exact date


Nifty Samsung code gets Galaxy fans this mobile for less


Sky TV block as brand-new crackdown interrupts UK homes from viewing content totally free