Hackers Impersonate Cybersecurity Firms In Callback Phishing Attacks - Insurance Claims News Article

Hackers Impersonate Cybersecurity Firms In Callback Phishing Attacks

Thursday, July 21st, 2022 Fraud

Hackers are impersonating well-known cybersecurity companies, such as CrowdStrike, in callback phishing emails to gain initial access to corporate networks.

Most phishing campaigns embed links to landing pages that steal login credentials or emails that include malicious attachments to install malware.

However, over the past year, threat actors have increasingly used "callback" phishing campaigns that impersonate well-known companies requesting you call a number to resolve a problem, cancel a subscription renewal, or discuss another issue.

When the target calls the numbers, the threat actors use social engineering to convince users to install remote access software on their devices, providing initial access to corporate networks.

This access is then used to compromise the entire Windows domain.


External References & Further Reading
https://www.bleepingcomputer.com/news/security/hackers-impersonate-cybersecurity-firms-in-callback-phishing-attacks/
SOS Ladder AssistMid-America Catastrophe ServicesAspen Claims ServiceNationwide OversprayU.S. Forensic