Scammers Use Milanote App to Host Phishing Content and Avoid Detection by Secure Email Gateways

Stu Sjouwerman | Jul 29, 2021

Milanote App Phishing ContentThe “Evernote for creatives” collaborative platform is being used to legitimately host malicious links that point victims to phishing links, bypassing detection mechanisms.

This isn’t the first time we’ve seen legitimate services being misused to host malicious content and links. Cloud-based services including Sharepoint, OneDrive, Dropbox, Google Drive, and many, many more have all been made use of by one threat actor or another over the years. The principle is simple: use a legitimate service to host malicious links, etc. hoping that the guise of it living on a known-good platform will be enough to throw off security solutions designed to detect malicious content.

In the case of a new attack discovered by security researchers at Avanan, the Milanote collaboration platform is the latest in the long list of misused services. According to Avanan, emails are sent under the guise of a due invoice, complete with attachment. The attachment contains a link to the Milanote platform which, in turn, contains a link to malicious content.

The good news for organizations is the creative effort put into this is so bad that it should be obvious to anyone that this is anything but an invoice:

L4Dm30cyWc6XfKOsyLtJ4UHRQfQak4tczjFxlP0m9A20Cc4IZF8xwBOOjif89a1XuidlWtcDntaxE0qMbuCW4s20mQvz8kR5T8zFQ8teMdmvsahFN25rzx1tSMr-2XVE0mmAwrJm

Source: Avanan

Users who have been educated using Security Awareness Training will spot this for what it is at the initial email, let alone the barren-looking initial link, or the supposed invoice PDF above. By teaching your users that these methods that require multiple steps to avoid detection should be a red flag, as an invoice should be nothing more than an attached PDF or a link to a legitimate invoicing site (e.g., Quick Books, Bill, etc.).

Topics: Phishing

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.