Threat Actors Mimic as HR Departments to Steal Your Gmail Login Credentials
A recent phishing campaign has been identified targeting job seekers by exploiting legitimate Zoom document-sharing features. This campaign aims to harvest Gmail credentials by impersonating HR departments and utilizing authentic Zoom notifications.
A recent phishing campaign has been identified targeting job seekers by exploiting legitimate Zoom document-sharing features. This campaign aims to harvest Gmail credentials by impersonating HR departments and utilizing authentic Zoom notifications.
The campaign starts with victims receiving emails purportedly from "HR Departments via Zoom Docs," with subjects such as "HR Departments invited you to view 'VIEW DOCUMENTS'." These emails successfully pass standard email authentication protocols, including SPF, DKIM, and DMARC verification, rendering them seemingly legitimate to both users and security systems.
The attackers focus on individuals actively seeking employment, leveraging their potential eagerness to engage with perceived job opportunities.
When victims click on the document link, they are redirected through a series of malicious websites. The initial redirect leads to overflow.qyrix.com.de, where a fake "bot protection" gate is presented. This gate serves to block automated security analysis tools and create an illusion of legitimacy for users.
A recent phishing campaign has been identified targeting job seekers by exploiting legitimate Zoom document-sharing features.
Upon completing a fraudulent CAPTCHA verification, users are taken to a phishing page that closely mimics Google's sign-in portal, complete with branding and interactive elements.
Real-Time Credential Exfiltration via WebSocket
The campaign employs real-time credential harvesting through WebSocket connections. Once victims enter their Gmail credentials, the data is immediately sent to the attackers' command and control server via an active WebSocket connection at overflow.qyrix.com.de/websocket/socket.io/.
Immediate validation of stolen credentials against Google's authentication systems. Faster data transmission compared to traditional HTTP POST requests, reducing detection opportunities.
Network analysis indicates that WebSocket traffic includes authentication tokens and session cookies, suggesting preparation for immediate account takeover following credential theft.
Based on reporting by Cyber Security News.
