Phishbait Follows Current Events

Stu Sjouwerman | Jul 12, 2021

Phishbait Current EventsCrisis draws opportunistic criminals, and the Kaseya ransomware incident is no different. Kaseya’s updates on the incident have included repeated warnings not to be taken in by emails or phone calls purporting to offer news, advice, or patches of the company’s VSA software.

“Spammers are using the news about the Kaseya Incident to send out fake email notifications that appear to be Kaseya updates. These are phishing emails that may contain malicious links and/or attachments,” the company posted on Friday, adding:

“Spammers may also be making phone calls claiming to be a Kaseya Partner reaching out to help. Kaseya IS NOT having any partners reach out – DO NOT respond to any phone calls claiming to be a Kaseya Partner.

“DO NOT click on any links or download any attachments in emails claiming to be a Kaseya advisory. However, some customers have subscribed to our support site and, at this point, those automated emails may contain links. As precaution, be careful with any links or attachments in any emails.”

Malwarebytes had noted last week that references to the Kaseya incident have begun appearing as phishbait in social engineering schemes, usually emails offering malicious links or attachments. The subjects suggest an offer of advice, warning, or counsel in the matter of the Kaseya exploit. “Threat actors often use opportunistic themes in their campaigns and we believe this is the case here,” Jerome Segura, Director of Threat Intelligence at Malwarebytes said. “This Kaseya fake update is a Cobalt Strike payload and interestingly hosted on the same IP address used for another campaign pushing Dridex. In the past we've seen the same threat actor behind Dridex using Cobalt Strike.”

Treat emails or phone calls of this kind with the same caution you’d apply to notices of automatic renewals of services you don’t remember signing up for, or appeals for your cooperation from foreign officials (or their widows). New school security awareness training can help your people develop resistance to these forms of social engineering.

Kaseya’s warnings, and their accompanying updates, may be found here. Malwarebytes’ tweet on the incident may be found here

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.