Cybercriminals are Using Geotargeted Phishing to Target Victims

Stu Sjouwerman | Feb 14, 2023

Geotargeted Phishing AttackAttackers are abusing a legitimate service called “GeoTargetly” to launch localized phishing attacks, according to Jeremy Fuchs at Avanan. GeoTargetly is meant to be used by advertisers to display ads in countries’ local languages. Avanan observed a phishing campaign that’s using phishing emails to target multiple countries in South America.

“The original email is essentially about a local traffic ordinance–which may not be enough to get people to click,” Fuchs explains. “However, the email itself is not what’s interesting–what is interesting is the ability for hackers to customize their attacks by region, and to attack multiple users in multiple parts of the world at once.”

Fuchs notes that the emails themselves are untargeted, and the attackers simply send out so many emails that some people are bound to fall for them.

“Spray-and-pray is a common technique of threat actors,” Fuchs says. “The idea–throw a bunch of things at the wall and see what sticks. The name of the game is volume, and you’re hoping for a few successful phishes here and there.”

In this case, however, the threat actors are using a new technique to make these campaigns somewhat more precise.

“[This attack] is a different kind of spray-and-pray,” Fuchs writes. “It allows for the ability for hackers to target a large number of people at once, and ensure that it’s relevant, and localized. It’s spraying without the praying. Using the GeoTargetly redirect, a hacker can create a phishing link that redirects users in a certain region to a fake login page that looks identical to the original one. This personalization increases the chances of a user falling for the attack. The redirect is legitimate and the content would be relevant to their language and region. This has increased the likelihood of spray and pray are working, and would allow hackers to operate on a global nature seamlessly.”

New-school security awareness training can give your employees a healthy sense of suspicion so they can avoid falling for social engineering attacks.

Avanan has the story.

Topics: Phishing

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.