Open Forum

 View Only
  • 1.  Security BUZZ - A Sneaky New Phishing Attack: Corrupted Word Documents

    Posted 12-13-2024 09:38

    There's a new phishing campaign that's using a clever trick - corrupted Word documents. This technique allows malicious content to pass through to the user without detection by any email security tools.

    The attacker intentionally (slightly) corrupts the attached Word document so that antivirus and security scanners can't scan it. Because the file has a .docx extension, when the unsuspicious victim opens it, Microsoft Word detects the corruption and asks the user if they want to repair it. If the user confirms, Word will repair and open the file.

    Inside the recovered file is a QR code that leads to a credential harvesting page that steals both the user's credential and the MFA.

    The timing of this attack is impeccable. Security firm Any.Run, which discovered it, found that the email appeared to come from Human Resources and focused on end-of-the-year benefits and bonus payouts.

    Takeaways:

    • Hackers frequently time and theme their attacks to seasonal, disaster or business events - always stay alert during business seasonality (i.e., end-of-month, quarter, year activities, benefits, payouts, income-tax events)
    • Attackers continuously attempt to find ways to stay under the radar of security technologies - always proceed with caution
      • Every attachment from an unknown source should be considered malicious until proven otherwise
      • Any new behavior (recovery of corrupted attachment) should be a red flag
    • QR codes have alarmingly become mainstream for cybercrooks due to the inability to analyze the destination with the naked eye. Scrutinize all QR codes and avoid using them in emails and attachments if possible.
    • Do not enter any credentials on the site you landed on from the email or attachments unless it came from a trusted and verified source

    #ALTACyber



    ------------------------------
    Genady Vishnevetsky
    Chief Info Security Officer
    Stewart Title Guaranty Company
    Houston TX
    ------------------------------
    ALTA Marketplace


  • 2.  RE: Security BUZZ - A Sneaky New Phishing Attack: Corrupted Word Documents

    Posted 12-16-2024 08:09
    Very much appreciate you keeping us apprised of these new schemes, Genady.  In this day and age, you definitely cannot let your guard down.

     

     
    Ellen Albrecht
    Senior Underwriter
    C: (402) 214-0209
    E: [email protected]
    727 N. Waco Ave., Ste 300 Wichita KS 67203
    O: (316) 267-8371
    Our offices will be closed on Tuesday, December 24 and Wednesday, December 25 for the Christmas Holiday.  We will also be closed on Wednesday, January 1, 2025 for New Year's Day.
    Visit us online for more resources, security1st.com.
    Security 1st Title License Numbers: CO-532633, IA-1741945, KS-15200817, MO-8324356, NE-100265053, NV-3607332, WY-21344396
    Licensed in KS & MO NPN 3191055
    WARNING: WIRE FRAUD IS RAMPANT. SECURITY 1ST TITLE WILL NEVER CHANGE OUR WIRING INSTRUCTIONS DURING A TRANSACTION. NEVER WIRE MONEY WITHOUT DOUBLE-CHECKING THE WIRE INSTRUCTIONS FROM THE BUSINESS YOU ARE SENDING FUNDS TO. Call a verified phone number of Security 1st Title to verify your wire details before sending funds. Always verify wiring instructions from any source sent via email by calling your escrow, loan officer, or qualified intermediary immediately at a trusted and verified telephone number, via a business card or verified company website. Security 1st Title is not responsible for wires sent by you to the wrong bank or account number.



    ALTA Marketplace


  • 3.  RE: Security BUZZ - A Sneaky New Phishing Attack: Corrupted Word Documents

    Posted 12-29-2024 14:03

    Genady:

    As always thank you so much for such important information and thank you for keeping us updated on all the ways criminal may attack us, your input is so valuable and highly appreciated, thank you a million times.



    ------------------------------
    Mary Enzi CAA
    Tax Solutions – FIRPTA Consulting
    [email protected]
    +1 (281) 578-1040
    Katy TX
    ------------------------------

    ALTA Marketplace