{"id":44463,"date":"2021-04-01T09:22:05","date_gmt":"2021-04-01T16:22:05","guid":{"rendered":"https:\/\/www.enxmag.com\/twii\/?p=44463"},"modified":"2021-04-01T11:20:40","modified_gmt":"2021-04-01T18:20:40","slug":"recent-phishing-scams-managed-to-bypass-email-security-filters","status":"publish","type":"post","link":"http:\/\/www.enxmag.com\/twii\/the-week-in-imaging-twii\/editors-blog\/2021\/04\/recent-phishing-scams-managed-to-bypass-email-security-filters\/","title":{"rendered":"Recent Phishing Scams Managed to Bypass Email Security Filters"},"content":{"rendered":"\n<div class=\"wp-block-image\"><figure class=\"alignleft size-medium\"><img loading=\"lazy\" width=\"300\" height=\"218\" src=\"https:\/\/www.enxmag.com\/twii\/wp-content\/uploads\/2021\/04\/Phish-300x218.jpg\" alt=\"\" class=\"wp-image-44464\" srcset=\"http:\/\/www.enxmag.com\/twii\/wp-content\/uploads\/2021\/04\/Phish-300x218.jpg 300w, http:\/\/www.enxmag.com\/twii\/wp-content\/uploads\/2021\/04\/Phish.jpg 362w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/figure><\/div>\n\n\n\n<p>Researchers at Armorblox describe several recent phishing scams that managed to bypass email security filters. The first attempted to gain access to users\u2019 Facebook accounts.<\/p>\n\n\n\n<p>\u201cRecently, the Armorblox threat research team observed an email impersonating Facebook attempt to hit one of our customer environments,\u201d Armorblox says. \u201cThe email was titled \u2018Reminder: Account Verification\u2019 with the sender name \u2018Facebook\u2019 and the sender domain \u2018noreply@cc[.]mail-facebook[.]com\u2019. The email informed victims that their account usage had been restricted due to some security concerns, and invited victims to verify their account activity to restore full access to their Facebook account.\u201d<\/p>\n\n\n\n<p>The email contains a link to a spoofed Facebook login page designed to steal the user\u2019s credentials.<\/p>\n\n\n\n<p>\u201cThe parent domain of the page is \u2018sliderdoyle[.]com\u2019, which should tell circumspect users that this isn\u2019t a legitimate site,\u201d the researchers write. \u201cHowever, the surface-level resemblance of the page to Facebook\u2019s real login portal combined with the urgency generated by the context of the email (restricted account access) means that many users will rush through this page and fill in their account details without looking at the URL.\u201d<\/p>\n\n\n\n<p>Another phishing email impersonated Apple and informed the recipient that their Apple account had been locked.<\/p>\n\n\n\n<p>\u201cThe email was titled \u2018Re: Your Apple ID has been locked on March 11, 2021 PST\u2019 followed by a reference number,\u201d Armorblox says. \u201cThe sender name was \u2018Appie ID\u2019, using a common technique of misspelling words to get past deterministic security techniques like filters\/blocklists while still passing victims\u2019 eye tests. The email informed victims that their Apple ID had been locked for security reasons. The email invited victims to verify their account within 12 hours of risk having their Apple ID suspended.\u201d<\/p>\n\n\n\n<p>In both of these cases, the scam could have been avoided if users had scrutinized the URL contained in the email. New-school security awareness training can help your employees recognize red flags associated with phishing attacks.<\/p>\n\n\n\n<p><em>This blog originally appeared on <a href=\"http:\/\/knowbe4.com\">KnowBe4<\/a>.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Researchers at Armorblox describe several recent phishing scams that managed to bypass email security filters. The first attempted to gain access to users\u2019 Facebook accounts. \u201cRecently, the Armorblox threat research team observed an email impersonating Facebook attempt to hit one of our customer environments,\u201d Armorblox says. \u201cThe email was titled \u2018Reminder: Account Verification\u2019 with the sender name \u2018Facebook\u2019 and the sender domain \u2018noreply@cc[.]mail-facebook[.]com\u2019. The email informed victims that their account usage had been restricted due to some security concerns, and invited victims to verify their account activity to restore full access to their Facebook account.\u201d The email contains a link to a spoofed Facebook login page designed to steal the user\u2019s credentials. \u201cThe parent domain of the page is \u2018sliderdoyle[.]com\u2019, which should tell circumspect users that this isn\u2019t a legitimate site,\u201d the researchers write. \u201cHowever, the surface-level resemblance of the page to Facebook\u2019s real login portal combined with the urgency generated by the context of the email (restricted account access) means that many users will rush through this page and fill in their account details without looking at the URL.\u201d Another phishing email impersonated Apple and informed the recipient that their Apple account had been locked. \u201cThe email was titled \u2018Re: Your Apple ID has been locked on March 11, 2021 PST\u2019 followed by a reference number,\u201d Armorblox says. \u201cThe sender name was \u2018Appie ID\u2019, using a common technique of misspelling words to get past deterministic security techniques like filters\/blocklists while still passing victims\u2019 eye tests. The email informed victims that their Apple ID had been locked for security reasons. The email invited victims to verify their account within 12 hours of risk having their Apple ID suspended.\u201d In both of these cases, the scam could have been avoided if users had scrutinized the URL contained in the email. New-school security awareness training can help your employees recognize red flags associated with phishing attacks. This blog originally appeared on KnowBe4.<\/p>\n","protected":false},"author":178,"featured_media":44464,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[80,1650,82,3371,1638],"tags":[3966],"_links":{"self":[{"href":"http:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/posts\/44463"}],"collection":[{"href":"http:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/users\/178"}],"replies":[{"embeddable":true,"href":"http:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/comments?post=44463"}],"version-history":[{"count":2,"href":"http:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/posts\/44463\/revisions"}],"predecessor-version":[{"id":44482,"href":"http:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/posts\/44463\/revisions\/44482"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/media\/44464"}],"wp:attachment":[{"href":"http:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/media?parent=44463"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/categories?post=44463"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/tags?post=44463"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}