The TodayZoo Phishing Kit Has All the Obfuscation and Impersonation Needed to Fool Your Users



TodayZoo Phishing KitNew details from Microsoft on this pieced-together phishing kit reveal some unique tactics designed to avoid detection by security solutions and users alike while stealing credentials.

TodayZoo has been around since the end of last year. But recent improvements have gotten the attention of Microsoft, who have documented the changes to TodayZoo in detail in a new blog.

The use of phishing kits makes is easier for threat actors to launch campaigns; rather than needing to create an attack and an ability to harvest credentials from scratch, they simply purchase the already created code.

What makes TodayZoo interesting is its use of obfuscation. There are a number of techniques used in their kits:

  • Zero-point-fonts – to avoid having their malware-less emails being detected as malicious (based on content), TodayZoo inserts the data invisibly into an email message, making the content less understandable to security solutions.
  • Randomly-generated domains – rather than spoofing the domain names of the accounts being phished, TodayZoo generates random 40 to 50-character subdomains under the domain hosting their malicious content.
  • Multiple Redirectors – the attacks consistently use initial and secondary redirector pages on compromised sites, a landing page to accept the user credentials, and a credential harvesting page to store the credentials locally on the site.
  • Spoofed logon pages – As expected, the logon page looks just like Microsoft’s making it undetectable to the eye… that is, unless you look at the URL!

Fig3-Phishing-page

 

 

 

 

 

 

 

Source: Microsoft

In short, this campaign is good enough to take inattentive users for a ride that ends with their account being compromised. One of your most impactful defenses is going to be Security Awareness Training designed to elevate a user’s personal sense of vigilance. Again, take the image above for example – all it takes is a slight glance upwards in the web browser to tell that it’s not really Microsoft’s logon page. Proper cybersecurity education can facilitate a vigilant user; and with TodayZoo, you’re going to need just that to remain secure.


Free Phishing Security Test

Would your users fall for convincing phishing attacks? Take the first step now and find out before bad actors do. Plus, see how you stack up against your peers with phishing Industry Benchmarks. The Phish-prone percentage is usually higher than you expect and is great ammo to get budget.

PST ResultsHere's how it works:

  • Immediately start your test for up to 100 users (no need to talk to anyone)
  • Select from 20+ languages and customize the phishing test template based on your environment
  • Choose the landing page your users see after they click
  • Show users which red flags they missed, or a 404 page
  • Get a PDF emailed to you in 24 hours with your Phish-prone % and charts to share with management
  • See how your organization compares to others in your industry

Go Phishing Now!

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/phishing-security-test-offer

Topics: Phishing



Subscribe to Our Blog


Comprehensive Anti-Phishing Guide




Get the latest about social engineering

Subscribe to CyberheistNews