Press ESC to close

Financially Motivated Threat Actor Leveraged Google Docs and Weebly Services to Target Telecom and Financial Sectors

Key DetailDescription
Threat ActorsFinancially motivated attackers targeting telecommunications and financial sectors.
Campaign OverviewPhishing campaign leveraging Google Docs and Weebly to target telecom and financial sectors, focusing on stealing credentials via fake login pages.
Target Regions (Or Victims)Telecommunications and financial sectors in the U.S., Canada, and Europe. Victims include telecom and financial institution employees.
MethodologyAttackers used Google Docs to deliver phishing links, leading victims to Weebly-hosted fake login pages. Dynamic DNS for subdomain rotation.
Product targetedTelecom and financial institution login pages, with tailored lures for brands like AT&T and a US-based financial institution.
Malware ReferenceNot mentioned.
Tools UsedGoogle Docs, Weebly, dynamic DNS, Sentry.io, Datadog, Snowplow Analytics, Google Analytics.
Vulnerabilities ExploitedPhishing via trusted platforms, MFA bypass, credential theft.
TTPsPhishing links, fake MFA prompts, dynamic DNS for evasion, tracking tools embedded in phishing pages.
AttributionFinancially motivated threat actors, specific attribution unclear.
RecommendationsEnhance email filtering for cloud documents, implement proactive DNS monitoring, enforce strong MFA, and improve phishing detection systems.
SourceEclecticIQ

Read full article: https://blog.eclecticiq.com/financially-motivated-threat-actor-leveraged-google-docs-and-weebly-services-to-target-telecom-and-financial-sectors

Disclaimer: The above summary has been generated by an AI language model

Source: EclecticIQ

Published on: November 21, 2024

Leave a Reply

Your email address will not be published. Required fields are marked *