Tuesday, 06 June 2023 03:42

Criminals are using this stupidly simple tactic to send malicious links - and it's working

Rate this item
(0 votes)

Criminals are using a remarkably straightforward tactic to try and direct victims to phishing links - but the bad news is that it appears to be working.

Usually, hackers would draft this elaborate email trying to convince the victims to click on a link found at the bottom of the message. These emails would either tell the recipients they urgently needed to download an antivirus or cancel a pending transaction that will leave them broke, or something similar.

However, cybersecurity researchers from Check Point Harmony Email have uncovered that some hackers are replacing all of that with a simple image. Instead of typing out a long email and risking being found out by typos or bad grammar, these attackers simply generate a promotional image - a flyer informing the recipients they’ve won a prize or are invited to participate in a some kind of competition.

Obvious scam

The picture would then be hyperlinked and would direct the victims to a phishing page where they’d give away sensitive information. Sometimes it’s just an email address, and sometimes it’s passwords, personally identifiable data that can be used in identity theft, and more.

Recipients with a keen eye would be able to quickly see through the fraud: all it takes is a hover of the mouse over the image for the hyperlink to appear. These links have nothing to do with the brands impersonated in the images, which is a clear red flag that a scam is afoot.

However, the researchers are saying the trick is working and that many people - instead of deleting the phishing email - end up clicking the image and falling prey to the attackers. 

Furthermore, by not displaying a link at all, hackers are succeeding in bypassing URL filters, one of the more popular methods of safeguarding inboxes.

To defend against such attacks, the researchers say IT teams should implement security that looks at all URLs and emulates the page behind it. They should also leverage URL protection that uses phishing techniques as an indicator of an attack, and deploy AI-based anti-phishing software capable of blocking such content across the entirety of the productivity suite.

 

TechRadar

March 08, 2025

Crude oil remained dominant export commodity as Nigeria posts N3.4trn trade surplus for Q4 2024

Nigeria achieved a trade surplus of N3.42 trillion in the fourth quarter of 2024, according…
March 07, 2025

Natasha suspended from Senate amid sexual harassment allegations against Senate President Akpabio

The Nigerian Senate has suspended Natasha Akpoti-Uduaghan, representing Kogi Central, for six months without pay…
March 08, 2025

Obesity rates soaring globally, study says

Rates of obesity and overweight are spiralling due to a "monumental societal failure" to tackle…
March 01, 2025

Man offers to split $525,000 jackpot with thieves who stole his credit card to buy…

A Frenchman appealed to the homeless thieves who stole his credit card to buy a…
March 04, 2025

Boko Haram intensifies attacks: 11 killed in Niger mining site raid, Professor abducted in Borno

In a series of escalating attacks, Boko Haram terrorists have struck again in northern Nigeria,…
March 08, 2025

What to know after Day 1108 of Russia-Ukraine war

WESTERN PERSPECTIVE Ukrainian forces fighting inside Russia are almost surrounded, open source maps show Thousands…
February 24, 2025

How AI is affecting the way kids learn to read and write

Kayla Jimenez For Lisa Parry, a 12th grade teacher in South Dakota, the students' essays…
January 08, 2025

NFF appoints new Super Eagles head coach

The Nigeria Football Federation (NFF) has appointed Éric Sékou Chelle as the new Head Coach…

NEWSSCROLL TEAM: 'Sina Kawonise: Publisher/Editor-in-Chief; Prof Wale Are Olaitan: Editorial Consultant; Femi Kawonise: Head, Production & Administration; Afolabi Ajibola: IT Manager;
Contact Us: [email protected] Tel/WhatsApp: +234 811 395 4049

Copyright © 2015 - 2025 NewsScroll. All rights reserved.