A Phishing Campaign Evades Email Gateways via WeTransfer

Stu Sjouwerman | Jul 25, 2019
wetransfer-logo

A phishing campaign is abusing the legitimate file hosting site WeTransfer to get malicious links through email filters, according to Jake Longden at Cofense. The attackers send real WeTransfer notifications via email, which inform recipients that someone has shared a file with them.

WeTransfer notifications let users include a comment in such emails to give the link context, and attackers are using this feature to tell the victim that the file is important.

When a victim clicks the link to receive their file, they’ll be taken to a WeTransfer page that will in turn download an HTML file. Opening this file will take the victim to the phishing page, which in this case spoofs an Office 365 login page.

The important thing to note here is that the entire delivery method is legitimate, so most email filters aren’t watching out for this behavior.

“As WeTransfer is a well-known and trusted file hosting system, used to share files too large to attach to an email, these links will typically bypass gateways as benign emails, unless settings are modified to restrict access to such file sharing sites,” Longden writes. “The PDC has observed this attack method to bypass multiple gateways.”

As security technologies adapt to known vectors of attack, threat actors are increasingly taking advantage of legitimate services to carry out phishing attacks. New-school security awareness training can help your employees keep up with new phishing techniques. Source: https://cofense.com/phishing-attackers-abusing-wetransfer-evade-email-gateways/


Find out how affordable new-school security awareness training is for your organization. Get a quote now.

 
Get A Quote
Request A Demo
 

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.