Cybercriminals Spoof German Media Anga Com Conference in New Phishing Campaign

Stu Sjouwerman | Jun 14, 2023

Phishing German ConferenceA phishing campaign is spoofing the major German media conference Anga Com, according to Jeremy Fuchs at Avanan.

“A central part of any conference for a company is to garner interest for their company,” Fuchs explains. “Many conferences will give over lead lists for companies to follow up on. This can be a significant source of potential revenue for companies. This is not the usual fare for hackers. But in a clever twist, hackers insert themselves into the lead delivery process to steal credentials by creating look-a-like webpages on easy-to-use and legitimate developer sites.”

The threat actors are targeting conference attendees with phony offers of business opportunities.

“There’s a lot going on in this attack,” Fuchs writes. “First, there’s the pure impersonation and social engineering of this popular conference. The hackers are using the name of the conference, and the dazzling potential of future business, to get users to click. That’s the first part, which requires fairly little expertise on the part of the hacker. If anything, it shows ingenuity by sending the email within a few days of the conference ending. Because companies tend to post that they are at such conferences on social media, it makes it easy for hackers to identify potential targets.”

The attackers are abusing the legitimate service Surge to host their phishing pages, which can help their emails bypass security scanners.

“What requires more skill is creating the look-a-like page,” Fuchs says. “Luckily for hackers, there are tools that help them along. In this case, it is Surge.sh Surge.SH is not a malicious site, but like many legitimate services, it can be used to foster illegitimate acts. By leveraging the legitimacy of Surge, it allows for the bypassing of security services. Users can spot the plot by seeing that the URL has the Surge domain in it. But even that is potentially tricky. Because Anga Com is in the name of the URL, users might think that Surge is the platform being used to host the leads.”

New-school security awareness training can teach your employees how to thwart phishing and other social engineering attacks.

Avanan has the story.

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.