Tax Phish Swims Past Google Workspace Email Security
#1
Information 
Quote:A W2 tax email scam is circulating in the U.S. using Typeform, a popular software that specializes in online surveys and form building. The campaign is aimed at harvesting victims’ email account credentials, researchers said.
 
According to Armorblox, the campaign also bypasses native Google Workspace email security filters in the victims it examined.
 
“The email impersonated an automated file-sharing communication from OneDrive, informing victims that they had received a file,” researchers explained in an analysis on Tuesday. “The email was sent from a Hotmail ID and was titled ‘RE: Home Loan,’ followed by a reference number and the date, making it seem like the email was part of an ongoing conversation to lend it more legitimacy.”
 
The links included in the emails purport to lead to a document called “2020_TaxReturn&W2.pdf,” researchers found. Instead, the links take users to a Typeform page where victims are asked to enter their email account credentials before being granted access to the file.
 
However, entering email account information into the form only returns error messages. After several attempts, the campaign surfaces a message saying that “the document is secured” and that the user’s identity could not be verified.
 
“It’s likely that the error messages could be a smokescreen for the attackers to gather as many account ID and password combinations as unsuspecting victims are willing to enter in an attempt to brute-force their way to gain access to the W2,” according to Armorblox. “In reality, there is no W2 pot of gold at the end of this malicious rainbow.”

Read more: Tax Phish Swims Past Google Workspace Email Security | Threatpost
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Messages In This Thread
Tax Phish Swims Past Google Workspace Email Security - by silversurfer - 14 April 21, 12:38

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
QOwnNotes
26.3.5  Disabled ...Kool — 10:15
Hasleo software (formerly called EasyUE...
Hasleo Backup Suite ...jasonX — 21:06
Hasleo Backup Suite V5.6.2.1
Hasleo Backup Suit...harlan4096 — 17:41
Opera 128.0.5807.52
Hello! New upda...harlan4096 — 17:39
Brave 1.87.192
Release v1.87.192 ...harlan4096 — 17:38

[-]
Birthdays
Today's Birthdays
avatar (45)tukraNax
Upcoming Birthdays
avatar (44)gapedDow
avatar (38)snorydar
avatar (43)Hectorvot
avatar (51)knowhanPluts
avatar (39)Williamengiz
avatar (46)qaqapeti
avatar (44)battsourIonix
avatar (43)CedricSek
avatar (39)chasRex
avatar (45)walllMIZ
avatar (41)oconyho
avatar (33)uteluxix
avatar (47)piafcflene
avatar (39)Matthewkah
avatar (51)tersfargum
avatar (50)alfreExept
avatar (38)Charlesfibre
avatar (42)napasvem
avatar (44)diploJeoca
avatar (38)francisnj3
avatar (43)artmaGoork
avatar (41)RichardCisee
avatar (40)ebenofit
avatar (38)ykazawu

[-]
Online Staff
There are no staff members currently online.

>