Cybercriminals are abusing Christmas delivery anxiety to harvest your credentials
Date:
Thu, 02 Dec 2021 14:36:55 +0000
Description:
If you get an email from DHL saying a parcel couldn't be delivered, exercise caution.
FULL STORY ======================================================================
Cybercriminals are capitalizing on Christmas delivery anxiety in an attempt
to steal email addresses, account passwords and other valuable information, experts have warned.
According to researchers from email security firm Avanan, an unnamed
malicious actor has kicked off a new phishing campaign, impersonating deliver company DHL.
The premise is simple: the victim receives an email message that looks like
it was sent by DHL, alerting them to a package that could not be delivered to their address. The person is then invited to log into their account, in order to rearrange delivery.
As usual with phishing emails, the login link is provided within the email. However, instead of redirecting the victim to the actual DHL site, it sends him to a fake, almost identical copy.
There, should the victim actually try to log in, the data is sent to the attackers command and control (C&C) center. Abusing the holidays
According to Avanan analyst Jeremy Fuchs, the campaign started in November, just in time for the holidays. He argues that whoever is behind the attack
has timed the campaign to fall between Black Friday and Christmas, at a time when most online shoppers will be expecting deliveries.
The researcher also claims theres a reason DHL was chosen, of all shipping companies; its the third-most impersonated brand, and delivers packages
across the globe.As consumers broadened their purchasing horizons this
holiday season, a DHL package is more believable, Fuchs claims.
The Covid-19 pandemic could also factor into the equation. The pandemic has wreaked havoc across supply chains all over the world, delaying shipments, leaving brick-and-mortar stores with empty shelves, and causing a scramble
for new tech gear ahead of Christmas. These are the best identity theft protection services around
======================================================================
Link to news story:
https://www.techradar.com/news/cybercriminals-are-abusing-christmas-delivery-a nxiety-to-harvest-your-credentials/
--- Mystic BBS v1.12 A47 (Linux/64)
* Origin: tqwNet Technology News (1337:1/100)