New “servicedesk.com” Phishing Attack Uses Microsoft, IBM Cloud Services to Add Legitimacy

Stu Sjouwerman | Jul 20, 2020

service desk phishing attackFocused on stealing victim credentials, this new attack uses a number of tactics to establish credibility, avoid raising red flags, and ensure they get the victim’s real credentials.

Security researchers at Bleeping Computer have identified a new phishing campaign that has some interesting ingenuity behind it. Sent under the premise that the potential victim has quarantined emails that need to be released by the mailbox owner, this new phishing campaign uses a from address of noreply@servicedesk.com, shown below.

spam-email

Source: Bleeping Computer

Under the hood, the use of servicedesk.com is helpful not only because it’s a term that may be familiar to a user, but also because the domain itself has no DMARC, DKIM, or SPF records to validate email senders.

Victims that click on the provided links are taken to web pages hosted on one of three enterprise cloud services – IBM Cloud, Microsoft Azure, or Microsoft Dynamics – complete with freely provided SSL certificates, all used to add credibility to links when scrutinized by security solutions.

Lastly, victims are then pushed to a spoofed logon page and are asked to authenticate. What makes this attack particularly impressive, is the authors built in password testing, so that should the victim be skeptical and put in a basic password (e.g., “12345678”), the logon page will reject the password with a “wrong password” error – again, adding legitimacy to the experience.

The bad guys are improving their understanding of the need to not just bypass security solutions, but – in essence – the user as well by creating an experience that feels “normal” to them. While the email in this case had some obvious poor choices of words and mixups of terms as obvious red flags, it still could pass for a user that isn’t paying attention. Users that undergo continual Security Awareness Training are taught to always be paying attention, skeptical of each and every email they interact with, regardless of who it’s from or what it’s about. It’s this heightened level of awareness that helps to protect organizations against phishing attacks, keeping credentials, networks, and data safe.

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the human and AI workforce to make safer security decisions every day. Trusted by over 70,000 organizations worldwide, we help strengthen security culture and manage risk. Our comprehensive AI-driven platform includes awareness and compliance training, cloud email security, real-time coaching, crowdsourced anti-phishing, AI Defense Agents, agent security and more. As the only global security platform of its kind, KnowBe4 provides personalized content, tools, and techniques to keep the modern workforce safe from phishing, vishing, deepfakes, and emerging threats.

Get the latest insights, trends and security news. Subscribe to CyberheistNews.