Universities Are Still Targeted With Phishing Attacks By Iranian Hackers

Stu Sjouwerman | Aug 25, 2018

cobalt-dickens-01

Secureworks® Counter Threat Unit™ (CTU) researchers reported that despite indictments in March 2018, the Iranian threat group is likely responsible for a large-scale campaign that targeted university credentials using the same spoofing tactics as previous attacks.

In August 2018, members of university communities worldwide may have been providing access to more than just homework assignments.

Secureworks CTU discovered a URL spoofing a login page for a university. Further research into the IP address hosting the spoofed page revealed a broader campaign to steal credentials. Sixteen domains contained over 300 spoofed websites and login pages for 76 universities located in 14 countries, including Australia, Canada, China, Holland, Israel, Japan, Switzerland, Turkey, the United Kingdom, and the United States.

The attacks used the tried-and-true social engineering tactic of phishing emails and spoofed login pages. Again a reminder that stepping your users through new-school security awareness training is not a nice-to-have... it's a must.

Full Story with list of spoofed domains here.


Now is a good time to review the 22 social engineering red flags to watch out for. It might be a good idea to print out this PDF and pass it along to family, friends, coworkers, students, etc. Remember to always think before you click!

22 Social Engineering Red Flags 

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.