By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Security Parrot - Cyber Security News, Insights and ReviewsSecurity Parrot - Cyber Security News, Insights and Reviews
Notification
Latest News
OpenAI may use Associated Press archive for AI training
July 14, 2023
EU users can hold conversations with Google Bard from training set
July 14, 2023
Aptos, the new default font for Microsoft Office
July 14, 2023
BlackLotus UEFI bootkit sources published on GitHub
July 14, 2023
Hackers from the XDSpy cyber-espionage group attacked Russian organizations on behalf of the Ministry of Emergency Situations
July 14, 2023
Aa
  • News
  • Tutorials
  • Security InsiderComing Soon
  • Expert InsightComing Soon
Reading: Snapchat and American Express sites used in Microsoft 365 phishing attacks
Share
Security Parrot - Cyber Security News, Insights and ReviewsSecurity Parrot - Cyber Security News, Insights and Reviews
Aa
Search
  • News
  • Tutorials
  • Security InsiderComing Soon
  • Expert InsightComing Soon
Follow US
Security Parrot - Cyber Security News, Insights and Reviews > News > Snapchat and American Express sites used in Microsoft 365 phishing attacks
News

Snapchat and American Express sites used in Microsoft 365 phishing attacks

Last updated: 2022/08/10 at 10:51 PM
Security Parrot Editorial Team Published August 10, 2022
Share
SHARE

Attackers used Open Redirects vulnerabilities on Snapchat and American Express in a series of phishing attacks to steal Microsoft 365 credentials.

Open Redirects are web application vulnerabilities that allow a hacker to use domains of trusted organizations and websites as temporary landing pages to facilitate phishing attacks. Open Redirects errors are used in attacks that redirect victims to malicious sites that either infect with malware or trick the victim into handing over sensitive information (credentials, payment and personal information, etc.).

“A trusted domain (eg American Express, Snapchat) acts as a temporary landing page before the user is redirected to a malicious site,” Inky explained in a published report.

Phishing emails impersonating Microsoft and FedEx

According to Inky researchers, open Snapchat redirects were used in 6,812 phishing emails sent from Google Workspace and Microsoft 365 hacked over 2.5 months. These emails impersonated Microsoft, DocuSign, and FedEx and redirected recipients to landing pages designed to collect Microsoft credentials.

Microsoft phishing page for data collection

Although the Snapchat vulnerability was reported by researcher ayushsinha31 via the Open Bug Bounty platform back on August 4, 2021, the Open Redirect bug is still unpatched.

In addition, the American Express redirect bug was fixed after it was exploited by attackers for several days at the end of July. American Express open redirect used in 2029 phishing emails using Microsoft Office 365 honeypots sent from newly registered domains to redirect potential victims to Microsoft credential harvesting sites.

“In the Snapchat and American Express exploits, the attackers inserted personal information into the URL so that malicious landing pages could be configured on the fly for individual victims. In both cases, this insertion was masked by converting it to Base 64 to make it look like a bunch of random characters,” explained Inky.

To protect against such attacks, experts have advised email recipients to check for “url=”, “redirect=”, “external-link”, “proxy”, or multiple occurrences of “HTTP” in URLs embedded in emails. Website owners are also encouraged to implement external redirect disclaimers that ask users to click before being redirected to external sites.

Weekly Updates For Our Loyal Readers!

Security Parrot Editorial Team August 10, 2022
Share this Article
Facebook Twitter Email Copy Link Print

Archives

  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • February 2023
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020

You Might Also Like

News

OpenAI may use Associated Press archive for AI training

July 14, 2023
News

EU users can hold conversations with Google Bard from training set

July 14, 2023
News

Aptos, the new default font for Microsoft Office

July 14, 2023
News

BlackLotus UEFI bootkit sources published on GitHub

July 14, 2023

© 2022 Parrot Media Network. All Rights Reserved.

  • Home
  • Parrot Media Group
  • Privacy Policy
  • Terms and Conditions
Join Us!

Subscribe to our newsletter and never miss our latest news, podcasts etc..

Zero spam, Unsubscribe at any time.

Removed from reading list

Undo
Go to mobile version
Welcome Back!

Sign in to your account

Lost your password?