Beware of Phony LogMeIn Security Updates

Stu Sjouwerman | May 27, 2020

logmein security updatesResearchers at Abnormal Security warn that a phishing campaign is trying to steal LogMeIn remote desktop credentials. The attackers are sending phishing emails that purport to come from LogMeIn, and they pretend to inform the recipient of an urgent security update.

The emails contain a link that appears to be a URL pointing to LogMeIn’s legitimate website, but this is actually anchor text (clickable text) posing as a URL, and the link behind it will take the user to a credential-harvesting phishing site that impersonates LogMeIn’s real sign-in page.

The researchers point out that, due to the current environment of pandemic-driven remote work, a fake security update is likely to be an effective lure for users of collaborative tools like LogMeIn.

“Other collaboration platforms have been under scrutiny for their security as many have become dependent on them to continue their work given the current pandemic,” they write. “Because of this, frequent updates have become common as many platforms are attempting to remedy the situation. A recipient may be more inclined to update because they have a strong desire to secure their communications.”

Additionally, the researchers note that LogMeIn uses single sign-on (SSO) with its subsidiary LastPass, so the attackers may be trying to gain access to victims’ password managers, which could potentially grant them access to all of the victims’ credentials.

The researchers say they’ve seen a spike in phishing campaigns targeting collaborative platforms, and they attribute this trend to the shift to remote working conditions.

“We’ve seen an incredible uptick in collaboration software impersonations in the past month,” they write. “Most of these platforms are associated with other logins (like G Suite or Office 365 logins) and can be leveraged by attackers to gain access to or assault other accounts.”

Once an attacker has compromised one account within your organization, they can use that account to launch more targeted attacks against other employees. New-school security awareness training can create a culture of security within your organization, enabling your employees to identify phishing emails and instilling in them the importance of multi-factor authentication.

Abnormal Security has the story: https://abnormalsecurity.com/blog/abnormal-attack-stories-logmein-phishing/

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.