University-themed Phishbait Angles for Students



University-themed PhishbaitResearchers at Zix have observed phishing emails sent from legitimate but compromised university email accounts, impersonating the university’s IT department. The emails notified users that their Office 365 password had expired, and directed them to click a link to keep their same password. The link led to a spoofed Office 365 login page designed to harvest their credentials.

“These email messages dissected above stood out to the Zix | AppRiver team because they managed to successfully bypass sender verification checks such as Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM) and Domain-based Message Authentication, Reporting and Conformance (DMARC),” the researchers write. “They also did not just simply spoof .EDU in the friendly-from/display address.”

This incident highlights why users need to consider the circumstances and content of emails, rather than assuming the messages are legitimate because they come from a trusted account. In this case, the format of the email’s text was strange-looking, with underscores between each letter, which could have tipped many users. Additionally, the link in the email led to a URL that didn’t remotely resemble an Office 365 site.

Many phishing emails are better-crafted than this one, however. The Zix researchers spotted a second email from a compromised university account that instructed recipients to click a link to upgrade their Outlook apps to the latest version. This email contained slight grammatical errors, but was much more convincing than the first email. The link led to a phishing portal hosted on Google Docs, rather than to a suspicious-looking domain.

If a recipient is unsure if an email is legitimate, they can reset their password by going directly to their account in a web browser, rather than clicking on a link in an email. They should also call the university’s IT department to alert them of a potential phishing campaign using compromised university accounts.

New-school security awareness training can help your employees identify phishing emails and respond appropriately.

Zix has the story.


Free Phishing Security Test

Would your users fall for convincing phishing attacks? Take the first step now and find out before bad actors do. Plus, see how you stack up against your peers with phishing Industry Benchmarks. The Phish-prone percentage is usually higher than you expect and is great ammo to get budget.

PST ResultsHere's how it works:

  • Immediately start your test for up to 100 users (no need to talk to anyone)
  • Select from 20+ languages and customize the phishing test template based on your environment
  • Choose the landing page your users see after they click
  • Show users which red flags they missed, or a 404 page
  • Get a PDF emailed to you in 24 hours with your Phish-prone % and charts to share with management
  • See how your organization compares to others in your industry

Go Phishing Now!

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/phishing-security-test-offer

Topics: Phishing



Subscribe to Our Blog


Comprehensive Anti-Phishing Guide




Get the latest about social engineering

Subscribe to CyberheistNews