Fears over cyber crime tool that can build phishing pages in real-time
Threat actors installed the LogoKit toolkit on over 700 domains over the last month
According to a report from security researchers at RiskIQ, the phishing kit, dubbed LogoKit, is fully modularized, allowing other threat actors to easily reuse and adapt it.
Employees behaving badly?
Why awareness training mattersDownload now
RiskIQ security researcher Adam Castleman said his company had observed more than 700 domains running with LogoKit. Targeted services range from generic login portals to false SharePoint portals, Adobe Document Cloud, OneDrive, Office 365, and cryptocurrency exchanges. RiskIQ has also observed attackers targeting several sectors, including financial, legal, and entertainment.
“Due to the simplicity of LogoKit, attackers can easily compromise sites and embed their script or host their own infrastructure. In some cases, attackers have been observed using legitimate object storage buckets, allowing them to appear less malicious by having users navigate to a known domain name, i.e., Google Firebase,” said Castleman.
Javvad Malik, security awareness advocate at KnowBe4, told ITPro this new attack shows how invested criminals are in phishing attacks.
“With each iteration, we see new techniques put in place designed to fool users into believing an email or website is legitimate,” Malik said.
Malik added that while technical controls can help to block some of these, they won't be successful all of the time.
“Which is why it's important to educate and train users to be able to identify and report any suspicious emails or websites. Organizations also need to have monitoring and threat detection controls in place so that if an attack is successful, then it can be detected and responded to in a timely manner before it becomes a full-blown incident,” he added.
The state of Salesforce: Future of business
Three articles that look forward into the changing state of Salesforce and the future of businessFree Download
The mighty struggle to migrate SAP to the cloud may be over
A simplified and unified approach to delivering Enterprise Transformation in the cloudFree Download
The business value of the transformative mainframe
Modernising on the mainframeFree Download
The Total Economic Impact™ Of IBM FlashSystem
Cost savings and business benefits enabled by FlashSystemFree Download