Cybercriminals Spoof German Media Anga Com Conference in New Phishing Campaign



Phishing German ConferenceA phishing campaign is spoofing the major German media conference Anga Com, according to Jeremy Fuchs at Avanan.

“A central part of any conference for a company is to garner interest for their company,” Fuchs explains. “Many conferences will give over lead lists for companies to follow up on. This can be a significant source of potential revenue for companies. This is not the usual fare for hackers. But in a clever twist, hackers insert themselves into the lead delivery process to steal credentials by creating look-a-like webpages on easy-to-use and legitimate developer sites.”

The threat actors are targeting conference attendees with phony offers of business opportunities.

“There’s a lot going on in this attack,” Fuchs writes. “First, there’s the pure impersonation and social engineering of this popular conference. The hackers are using the name of the conference, and the dazzling potential of future business, to get users to click. That’s the first part, which requires fairly little expertise on the part of the hacker. If anything, it shows ingenuity by sending the email within a few days of the conference ending. Because companies tend to post that they are at such conferences on social media, it makes it easy for hackers to identify potential targets.”

The attackers are abusing the legitimate service Surge to host their phishing pages, which can help their emails bypass security scanners.

“What requires more skill is creating the look-a-like page,” Fuchs says. “Luckily for hackers, there are tools that help them along. In this case, it is Surge.sh Surge.SH is not a malicious site, but like many legitimate services, it can be used to foster illegitimate acts. By leveraging the legitimacy of Surge, it allows for the bypassing of security services. Users can spot the plot by seeing that the URL has the Surge domain in it. But even that is potentially tricky. Because Anga Com is in the name of the URL, users might think that Surge is the platform being used to host the leads.”

New-school security awareness training can teach your employees how to thwart phishing and other social engineering attacks.

Avanan has the story.


Free Phishing Security Test

Would your users fall for convincing phishing attacks? Take the first step now and find out before bad actors do. Plus, see how you stack up against your peers with phishing Industry Benchmarks. The Phish-prone percentage is usually higher than you expect and is great ammo to get budget.

PST ResultsHere's how it works:

  • Immediately start your test for up to 100 users (no need to talk to anyone)
  • Select from 20+ languages and customize the phishing test template based on your environment
  • Choose the landing page your users see after they click
  • Show users which red flags they missed, or a 404 page
  • Get a PDF emailed to you in 24 hours with your Phish-prone % and charts to share with management
  • See how your organization compares to others in your industry

Go Phishing Now!

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/phishing-security-test-offer



Subscribe to Our Blog


Comprehensive Anti-Phishing Guide




Get the latest about social engineering

Subscribe to CyberheistNews