Story image

Cybercriminals taking over email accounts and scamming contacts

04 May 2018

A method of cybercrime that is becoming more and more popular of late is to take over a victim’s email account and attack their contacts.

That’s according to Barracuda VP email security Asaf Cidon, who says it’s simple – you’d be more inclined to open and act on an email from a colleague, friend, or at the very least someone you know as opposed to someone you don’t.

“Cybercriminals take over user accounts and send fake emails to the users’ colleagues and contacts. The emails sent contain fake links, including a fake OneDrive share link that is used to steal credentials and take over more accounts,” says Cidon.

Barracuda have provided an example of how criminals took over an account of a finance employee – most likely by following a phishing link from the attackers, which prompted them to enter their credentials into a fake Outlook sign-in page.

Once the criminals had the victim’s credentials, they then sent out emails to more than a dozen members of the finance team from the compromised account, with the goal being to steal additional credentials. Here’s the message that was sent:

The message seems quite innocent on its own, but Cidon says if the recipients click on the link they’ll be taken to a fake Office 365 sign-in where they’ll be asked to enter their credentials – if they do, then their accounts will be taken over by the criminals as well.

“On their own, stolen credentials of a reputable organisation are worth a handsome sum in the dark web. They can be sold to launch additional phishing campaigns, which will have a high chance of success since it would be coming from a high-reputation domain,” says Cidon.

“In addition, these stolen credentials can be used to conduct spear phishing, or CEO fraud attacks. In these attacks, the hackers send an email from the compromised account with the goal of tricking the recipient (who is usually in the finance department) to send a wire transfer to a bank account owned by the attacker.”

Cidon says there are a number of variants of emails that cybercriminals use to steal credentials – Barracuda have provided an example where the phishing email was sent out to users including a OneDrive share link in the body.

“Similar to what we saw in the first example, a user’s email account was also taken over; however, this time the criminals took a different approach with the included link. They included a OneDrive share link that when clicked, will lead to a fake sign-in page used to steal credentials,” says Cidon.

“In this particular attack, the criminals logged in multiple times to the user’s account, gathered targets from the user’s address book, and sent out hundreds of emails to both employees and external contacts.”

It’s clear that as soon as criminals have credentials the attacks are able to snowball rapidly. Cidon says what’s really scary is that standard email security solutions won’t detect these types of attacks because they originate from internal emails.

To recap, the techniques used in these attacks are:

Phishing: Emails are sent out to users to initiate the attack to steal their credentials.
Impersonation: Criminals impersonate colleagues or contacts to get users to act on their requests.

Barracuda recommends investing in email security solutions and enforcing user training and awareness.

Enterprise cloud deployments being exploited by cybercriminals
A new report has revealed a concerning number of enterprises still believe security is the responsibility of the cloud service provider.
Ping Identity Platform updated with new CX and IT automation
The new versions improve the user and administrative experience, while also aiming to meet enterprise needs to operate quickly and purposefully.
Venafi and nCipher Security partner on machine identity protection
Cryptographic keys serve as machine identities and are the foundation of enterprise information technology systems.
Machine learning is a tool and the bad guys are using it
KPMG NZ’s CIO and ESET’s CTO spoke at a recent cybersecurity conference about how machine learning and data analytics are not to be feared, but used.
Popular Android apps track users and violate Google's policies
Google has reportedly taken action against some of the violators.
How blockchain could help stop video piracy in its tracks
An Australian video tech firm has successfully tested a blockchain trial that could end up being a welcome relief for video creators and the fight against video piracy.
IBM X-Force Red & Qualys introduce automated patching
IBM X-Force Red and Qualys are declaring a war on unpatched systems, and they believe automation is the answer.
Micro Focus acquires Interset to improve predictive analytics
Interset utilises user and entity behavioural analytics (UEBA) and machine learning to give security professionals what they need to execute threat detection analysis.