Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / New
Stats: 3,163,126 members, 7,852,836 topics. Date: Friday, 07 June 2024 at 06:43 AM

Microsoft Cautions On Todayzoo Phishing Kit Used In Credential Stealing Attacks - Computers - Nairaland

Nairaland Forum / Science/Technology / Computers / Microsoft Cautions On Todayzoo Phishing Kit Used In Credential Stealing Attacks (186 Views)

Why Microsoft Windows OS Is Widely Used In Nigeria / What Tools Do You Use To Prevent Phishing? / EFCC Docks Suspect Over Alleged Computer Phishing (2) (3) (4)

(1) (Reply)

Microsoft Cautions On Todayzoo Phishing Kit Used In Credential Stealing Attacks by Jackfarrow: 10:09am On Oct 25, 2021
An extensive series of credential phishing campaigns has been discovered and disclosed by Microsoft on Thursday. This campaign is taking advantage of custom phishing kit that stitched together components from at least five different circulated ones with the aim of siphoning user login information.

This discovery was first made in December 2020 and dubbed the copy-and-paste attack infrastructure “TodayZoo”.

Researchers have stated that “availability of numerous phishing kits for sale and for rent makes it easy for a lone wolf attacker to pick and choose the best features from these kits, they put these functionalities together in a customized kit and try to reap the benefits all to themselves. Such is the case of TodayZoo.”

The TodayZoo phishing campaign impersonates Microsoft, posing as a password reset or fax and scanner notifications, to redirect victims to credential harvesting pages.

Large part of TodayZoo is believed to have been lifted generously from another kit known as DanceVida, while imitation and obfuscation-related components significantly overlap with the code from at least four other phishing kits such as Botssoft, WikiRed, Office-RD117 and Zenfo.



“This research further proves that most phishing kits observed or available today are based on a smaller cluster of larger kit ‘families,'” Microsoft’s analysis read. “While this trend has been observed previously, it continues to be the norm, given how phishing kits we’ve seen share large amounts of code among themselves.”

TodayZoo however deviates from DanceVida with regards to the credential harvesting component by replacing the original functionality with its own exfiltration logic.


Source : https://slytech.org/2021/10/25/microsoft-cautions-on-todayzoo-phishing-kit-used-in-credential-stealing-attacks/

(1) (Reply)

Please Help With This Keyboard Shortcut / UFI UFS Prog / Hp Compaq 6530b Intel Core 2 Duo @2.40ghz Hdd 160gb 3gb Ram

(Go Up)

Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health
religion celebs tv-movies music-radio literature webmasters programming techmarket

Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10)

Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 6
Disclaimer: Every Nairaland member is solely responsible for anything that he/she posts or uploads on Nairaland.