New details from Microsoft on this pieced-together phishing kit reveal some unique tactics designed to avoid detection by security solutions and users alike while stealing credentials.
TodayZoo has been around since the end of last year. But recent improvements have gotten the attention of Microsoft, who have documented the changes to TodayZoo in detail in a new blog.
The use of phishing kits makes is easier for threat actors to launch campaigns; rather than needing to create an attack and an ability to harvest credentials from scratch, they simply purchase the already created code.
What makes TodayZoo interesting is its use of obfuscation. There are a number of techniques used in their kits:
- Zero-point-fonts – to avoid having their malware-less emails being detected as malicious (based on content), TodayZoo inserts the data invisibly into an email message, making the content less understandable to security solutions.
- Randomly-generated domains – rather than spoofing the domain names of the accounts being phished, TodayZoo generates random 40 to 50-character subdomains under the domain hosting their malicious content.
- Multiple Redirectors – the attacks consistently use initial and secondary redirector pages on compromised sites, a landing page to accept the user credentials, and a credential harvesting page to store the credentials locally on the site.
- Spoofed logon pages – As expected, the logon page looks just like Microsoft’s making it undetectable to the eye… that is, unless you look at the URL!
Source: Microsoft
In short, this campaign is good enough to take inattentive users for a ride that ends with their account being compromised. One of your most impactful defenses is going to be Security Awareness Training designed to elevate a user’s personal sense of vigilance. Again, take the image above for example – all it takes is a slight glance upwards in the web browser to tell that it’s not really Microsoft’s logon page. Proper cybersecurity education can facilitate a vigilant user; and with TodayZoo, you’re going to need just that to remain secure.