The TodayZoo Phishing Kit Has All the Obfuscation and Impersonation Needed to Fool Your Users

Stu Sjouwerman | Nov 9, 2021

TodayZoo Phishing KitNew details from Microsoft on this pieced-together phishing kit reveal some unique tactics designed to avoid detection by security solutions and users alike while stealing credentials.

TodayZoo has been around since the end of last year. But recent improvements have gotten the attention of Microsoft, who have documented the changes to TodayZoo in detail in a new blog.

The use of phishing kits makes is easier for threat actors to launch campaigns; rather than needing to create an attack and an ability to harvest credentials from scratch, they simply purchase the already created code.

What makes TodayZoo interesting is its use of obfuscation. There are a number of techniques used in their kits:

  • Zero-point-fonts – to avoid having their malware-less emails being detected as malicious (based on content), TodayZoo inserts the data invisibly into an email message, making the content less understandable to security solutions.
  • Randomly-generated domains – rather than spoofing the domain names of the accounts being phished, TodayZoo generates random 40 to 50-character subdomains under the domain hosting their malicious content.
  • Multiple Redirectors – the attacks consistently use initial and secondary redirector pages on compromised sites, a landing page to accept the user credentials, and a credential harvesting page to store the credentials locally on the site.
  • Spoofed logon pages – As expected, the logon page looks just like Microsoft’s making it undetectable to the eye… that is, unless you look at the URL!

Fig3-Phishing-page

 

 

 

 

 

 

 

Source: Microsoft

In short, this campaign is good enough to take inattentive users for a ride that ends with their account being compromised. One of your most impactful defenses is going to be Security Awareness Training designed to elevate a user’s personal sense of vigilance. Again, take the image above for example – all it takes is a slight glance upwards in the web browser to tell that it’s not really Microsoft’s logon page. Proper cybersecurity education can facilitate a vigilant user; and with TodayZoo, you’re going to need just that to remain secure.

Topics: Phishing

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.