sb-nz logo
Story image

Cybercriminals taking over email accounts and scamming contacts

04 May 2018

A method of cybercrime that is becoming more and more popular of late is to take over a victim’s email account and attack their contacts.

That’s according to Barracuda VP email security Asaf Cidon, who says it’s simple – you’d be more inclined to open and act on an email from a colleague, friend, or at the very least someone you know as opposed to someone you don’t.

“Cybercriminals take over user accounts and send fake emails to the users’ colleagues and contacts. The emails sent contain fake links, including a fake OneDrive share link that is used to steal credentials and take over more accounts,” says Cidon.

Barracuda have provided an example of how criminals took over an account of a finance employee – most likely by following a phishing link from the attackers, which prompted them to enter their credentials into a fake Outlook sign-in page.

Once the criminals had the victim’s credentials, they then sent out emails to more than a dozen members of the finance team from the compromised account, with the goal being to steal additional credentials. Here’s the message that was sent:

The message seems quite innocent on its own, but Cidon says if the recipients click on the link they’ll be taken to a fake Office 365 sign-in where they’ll be asked to enter their credentials – if they do, then their accounts will be taken over by the criminals as well.

“On their own, stolen credentials of a reputable organisation are worth a handsome sum in the dark web. They can be sold to launch additional phishing campaigns, which will have a high chance of success since it would be coming from a high-reputation domain,” says Cidon.

“In addition, these stolen credentials can be used to conduct spear phishing, or CEO fraud attacks. In these attacks, the hackers send an email from the compromised account with the goal of tricking the recipient (who is usually in the finance department) to send a wire transfer to a bank account owned by the attacker.”

Cidon says there are a number of variants of emails that cybercriminals use to steal credentials – Barracuda have provided an example where the phishing email was sent out to users including a OneDrive share link in the body.

“Similar to what we saw in the first example, a user’s email account was also taken over; however, this time the criminals took a different approach with the included link. They included a OneDrive share link that when clicked, will lead to a fake sign-in page used to steal credentials,” says Cidon.

“In this particular attack, the criminals logged in multiple times to the user’s account, gathered targets from the user’s address book, and sent out hundreds of emails to both employees and external contacts.”

It’s clear that as soon as criminals have credentials the attacks are able to snowball rapidly. Cidon says what’s really scary is that standard email security solutions won’t detect these types of attacks because they originate from internal emails.

To recap, the techniques used in these attacks are:

Phishing: Emails are sent out to users to initiate the attack to steal their credentials. Impersonation: Criminals impersonate colleagues or contacts to get users to act on their requests.

Barracuda recommends investing in email security solutions and enforcing user training and awareness.

Story image
Gartner reveals the top strategic tech trends for 2021
“CIOs are striving to adapt to changing conditions to compose the future business - this requires the organisational plasticity to form and reform dynamically. Gartner’s top strategic technology trends for 2021 enable that plasticity.”More
Story image
How to secure your business against DDoS Attacks
With the upward trend of DDoS attacks this year, and an increased dependency on online channels across all industries, businesses need to be prepared, so they don’t suffer any disruption. More
Story image
Gigamon and Zscaler release cloud-first network detection for fluid workforces
“Our customers have significantly accelerated their digital transformation journeys during the pandemic, and this integration will help them better respond to threats.”More
Story image
Google Cloud observes spike in DDoS volumes in last two years
Google Cloud has seen an ‘exponential’ rise in distributed denial of service (DDoS) attacks over the past decade, but the biggest attacks have only occurred in the past couple of years.More
Story image
How to address cyber-threats as a strategic risk
Becoming a cyber-secure organisation in the face of an evolving threat landscape requires a strategic, business-focused approach to security as opposed to a tactical approach in which security is addressed simply by implementing new tools.More
Story image
Lumen launches managed security services for APAC market
The new service is designed to provide enterprise businesses with a proactive, connected security strategy to enhance threat detection and protection across endpoints. More