Cado Security Labs(现为Darktrace旗下)发现了一项针对科技行业高管的DocuSign矛鱼式邮件活动 1。攻击者冒充DocuSign发送恶意邮件,邮件中包含重定向到虚假登录页面的链接,意图窃取用户凭证 1。被盗凭证随后被用于商业电子邮件欺诈(BEC)等后续攻击 1。
此次活动的技术特征表明攻击者采用了多层欺骗手段 1。攻击者利用被入侵的日本企业邮箱域名(包括@anabuki-enter.co.jp和@jaog.or.jp)发送钓鱼邮件,以此规避DMARC安全检查 1。恶意邮件中的JavaScript代码经过base64编码混淆,脚本名称为NdoGg8EElI,用于伪造合法的DocuSign登录界面 1。钓鱼网站则托管在blegabouc[.]com和yperbole9[.]com两个域名上 1。
为防范此类威胁,安全建议包括启用双因素认证、验证发件人真实身份、对未通过SPF/DKIM/DMARC验证的邮件进行标记,以及直接通过DocuSign账户而非邮件链接验证文件真实性 1。
Cado Security Labs, now part of Darktrace, has identified a sophisticated phishing campaign leveraging fraudulent DocuSign emails to target technology industry executives 1. The attackers exploit compromised Japanese business email accounts to send malicious messages containing links that redirect victims to credential-harvesting websites, bypassing DMARC authentication checks in the process 1.
The campaign employs obfuscated JavaScript code, including a script named NdoGg8EElI encoded in base64, to create fake login pages designed to steal user credentials 1. The phishing domains used in the attacks include blegabouc[.]com and yperbole9[.]com 1. Once credentials are obtained, threat actors use the stolen information to conduct further attacks, including business email compromise (BEC) schemes 1.
To mitigate exposure to this threat, security experts recommend enabling two-factor authentication, carefully verifying sender addresses before responding to DocuSign communications, flagging emails that fail SPF, DKIM, and DMARC verification, and validating document authenticity directly through DocuSign accounts 1.
评论
还没有评论,欢迎留下第一条。