Phishing Campaign Impersonates Zix Messages

Stu Sjouwerman | Oct 1, 2021

Phishing Campaign Zix MessagesResearchers at Armorblox have spotted a credential phishing campaign that’s impersonating encrypted communications from Zix. The emails contain a link to download an HTML attachment.

“This email is titled ‘Secure Zix message’, includes a header in the email body reiterating the email title, and claims that the victim has received a secure message from Zix, which is a security technology company that provides email encryption and email data loss prevention services,” the researchers write. “The email invites the victim to click on the ‘Message’ button to view the secure message.”

The phishing campaign was widespread, but the researchers observed some attacks that were targeted at specific employees.

“Although the potential account exposure of this attack campaign was close to 75,000 mailboxes, our threat research team found that a select group of employees - usually across departments - were targeted within each customer environment,” Armorblox says. “For example, for one of our SLED customers, people targeted by this attack included the CFO, a Director of Operations, a Director of Marketing, and a Professor. For another customer, a wellness company, the target employees included the SVP of Finance and Operations, the President, and a utility email alias (member.services@company[.]com).”

Armorblox concludes that users should slow down and think before clicking on unsolicited links.

“Since we get so many emails from service providers, our brains have been trained to quickly execute on their requested actions,” the researchers write. “It’s much easier said than done, but engage with these emails in a rational and methodical manner whenever possible. Subject the email to an eye test that includes inspecting the sender name, sender email address, language within the email, and any logical inconsistencies within the email (e.g. Why is a Zix link leading to an HTML download? Why is the sender email domain from a third-party organization?).”

New-school security awareness training with simulated phishing attacks can enable your employees to thwart social engineering attacks.

Armorblox has the story.

Topics: Phishing

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.