Latest Netflix-Impersonated Phishing Attacks Surge in Frequency by 78% Since October

Stu Sjouwerman | Dec 2, 2022

Netflix-Impersonated PhishingUsing a mix of invisible and lookalike characters, this phishing attack attempts to get past security scanners by obfuscating both email content and domain names.

We covered a Netflix-related phishing attack earlier last month claiming the recipient’s account was suspended. According to email security vendor, Egress, this attack – and others like it – have resulted in a massive uptick in phishing attacks impersonating the on-demand video giant. Over half of attacks (52%) mention Netflix’s new ad-tier membership package to add legitimacy and drive engagement from potential victims.

According to Egress, the attackers use rare Unicode characters “that the linguistic engines of many secure email gateways (SEGs) are unable to pick up on.” Two examples given by Egress include a homograph attack where the domain is registered using international characters that look like ‘xn–pple-43d.com’, but would be translated by a browser to ‘аpple.com’, as well as a Unicode characters used in email subjects to avoid detection by scanning engines, as shown below in an example where the characters were displayed:

unicode-characters-in-subject-line

Source: Egress

This level of craftiness far surpasses the typical level of attentiveness paid by a user that isn’t concerned about cyberattacks. Users need to be educated with Security Awareness Training to be in a constant state of vigilance when any unexpected email comes in. Assume it’s malicious until proven otherwise.

Topics: Phishing

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.