Phishing Case 3 – What happened?

The following is something else that happened to me, I spotted it, and still clicked on a link!  Here is what happened. 

One of my clients I am moderately regularly in contact with sent me a message. I have copied it below. What is unusual about this message is other than the graphic, it contains no context. Most communications where you need someone to do something, you provide some context on what you want to them to do, when you want them to do it and why.  An email with not much more in it than a link is always suspicious. Even though I know the person sending it. 

On receiving this I sent back the following message:

“Is this from you? What is it for?”

“I would never open an attachment without a message accompanying it. Spam often looks like this and carries malicious links.”

Mark

I immediately got a reply back:

With that assurance, although there were still questions in my head, I took it at face value and clicked on the link. Note the link is obfuscated, which means you have no idea where it will go. But I trusted the sender. The only legitimate reason for obfuscating a link is to make a long link shorter.

When I clicked on the link this happened:

I use ESET Smart Security Premium on my systems for this very reason. My computer detected that the website was suspect before I got there. So no damage was done.  ESET Smart Security Premium manages the connections in and out of your computer as well as checking what is happening on any web accesses and performing virus checking. So more comprehensive than your normal AV program. 

Taking it all apart

There was a clue in the original email if you check it by scrolling back up. It was not sent to anyone. I missed that. It was sent to a lot of people who came from the person’s address book, they were all on the BCC line of the email. 

The response I got back allegedly from the “manager” was actually the hacker who was in the email account and monitoring it at the time. The real manager played no role in this at all. Even though they were logged into email as well. 

If you think about it, what was happening here was a hacker had got hold of someone’s email address and password. They silently logged in and were passively monitoring the inbox after the message went out. That is really what makes this, and other examples of it quite scary. 

In the response back the graphic had changed to an obfuscated link. There would be no reason to hide where it was really going to. 

What did I do next?

I tried to independently contact the manager, I was unsuccessful because the office was closed, that is twice this has happened on different occassions when the parent organisation was closed, was that a deliberate ploy?  I then tried several other people and eventually made the organisation aware of what was going on.  It turns out my wife, who handles my accounts under a different email address also got one of these messages, and several other people as well.  So it does look like the hacker was working through an address list associated with the account. 

What can you do?

This really is a very worrying example of a trend that is increasing at the moment. Most of us would not know if someone else was passively monitoring our email account. The fact that they had the address book as well is also of concern. 

My advice is as follows:

  • Be super vigilant on any emails, text messages or anything else carrying a link, particularly if there is no message or context, even if it is someone you know. Don’t just assume it is ok. 
  • Was the email addressed to you, or is the to line empty?  If it is empty it is likely to not be legitimate, because the true addresses are hidden on the bcc line. It is a broadcast message. 
  • If you are even 10% unsure, independently ring them up and check. I trusted email, and ended up being mislead by the hacker. 
  • Be particularly vigilant if you are on Outlook.com, this was targeting Sharepoint users where you would need to login with your Outlook email address. 
  • If you do go to a phishing site, they will generally look official and familiar. However check the website address. The example above was sending me to https://canyouheal.org. Which is probably an innocent site that a hacker has got into and placed a phishing page in there, unbeknown to the website owner. 
  • Make sure your device is protected by a good quality (aka NOT FREE) Anti Virus AND Security product. If all else fails that will likely save you. 
  • If it happens to you, first change your password to a strong password containing upper and lower case letters and numbers, and even symbols.  Next run your anti virus application to make sure your machine is clean. 
  • Communicate:  If you have seen it, tell everyone to warn them. It is highly likely that others may be exposed as well. 
  • Check your sent messages folder from time to time. A careless hacker may leave an evidence trail behind if he has intercepted some message threads. 
  • If you are affected by a Phishing site (where you put your email address and password in and nothing happens), after you have recovered your password with a new one, bear in mind, you also need to change the passwords for any critical interfaces and websites you have access too. Especially if you use your email address to recover a password!

This is becoming a very dangerous trend over the past few months. 

It is also wise to change your main email address password regularly as a precaution against this type of risk. 

 

 

Wingrove-Services
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

You can adjust all of your cookie settings by navigating the tabs on the left hand side.

My privacy policy can be located here: Wingrove Media Privacy Policy (opens in a new window)

My Cookies Policy can be found here: Wingrove Media Cookies Policy (opens in a new window)