Researchers Find New Calendar-Based Phishing Campaign

Researchers have once again spotted crooks using avg.com/retail     calendar invitations to mount phishing attacks Install Avg With License Number activation. The Confense Phishing Defense Center  avg internet security found the attack in enterprise email environments avg.com/activation protected by Proofpoint and Microsoft, it announced last week www.avg.com/activation .

The phishing scam uses iCalendar, which is a media type that lets users store and exchange calendaring and scheduling information, including events and tasks. iCalendar files are usually delivered with an .ics extension avg internet security. The company found the attackers www.avg.com/activate using this file with the subject "Fault Detection from Message Center," from a sender with the display name  www.avg.com/activation Walker avg.com/retail    . It came from a legitimate account belonging Install Avg With License Number activation to a school district, indicating avg.com/activation that the attackers were using a compromised email. That enabled them to bypass www.avg.com/activation  email filters relying on the DKIM and SPF technologies that authenticate sending domains.

When the victim opens the .ics file, it proposes a calendar entry displaying the URL, along with a message saying www.avg.com/activate that it is from a security center avg.com/retail    . The web page behind the URL is hosted on Microsoft's Install Avg With License Number activation SharePoint site avg.com/activation, and displays avg internet security another link to a phishing site hosted by Google that appears to show a Wells Fargo login page www.avg.com/activation .

Victims gullible enough to cooperate avg.com/retail     must submit their login details, PIN and account numbers www.avg.com/activation , along with their email credentials avg internet security. Doing so hands the attackers the keys to the kingdom avg.com/activation. The phishing site will then send them to the legitimate Install Avg With License Number activation Wells Fargo website to quell any suspicion www.avg.com/activate.

This may be a new campaign www.avg.com/activate, but it is not a new technique avg.com/retail    . A similar attack cropped up last June, when Kaspersky found attackers using Google's www.avg.com/activation  auto-add feature. In that attack, smartphone users Install Avg With License Number activation would see the invitation as a pop-up invitation avg internet security, displaying a link to a phishing URL avg.com/activation that asked for their credit card data and personal information.

Comments

Popular posts from this blog

Reasons You Should Upgrade to Windows 10

Cybersecurity vs. Information Security vs. Network Security

AVG and Avast merge together with shareholder payments