Gone Phishing

Cyber criminals are busy too. Not a day goes by without receiving emails from unknown sources in an attempt to steal credentials.

Figure 2 shows cleverly crafted HTML (web) pages with fake login forms to view documents. Completing these forms will send the credentials back to a command and control server where it’ll be sold and/or misused for malicious activity. One should be wary of emails containing HTML files or links to pages like these and not complete the form, deleting the email as soon as possible.

Figure 2: Tax Invoice Phishing Scheme