I spotted this interesting phishing campaign that (ab)uses the McAfee antivirus to make people scared. It starts with a classic email that notifies the targeted user that a McAfee subscription expired: The mail is not very well designed but it attracts the victim because it uses classic social engineering techniques:
When the victim clicks on the "Buy now" link, the following URL is reached: hxxps://r-trk[.]loumous[.]com/ga/click/2-51298608-3418-77390-152728-118643-69c53876cd-1807191af3 This website simulated an antivirus scan and, of course, the computer is infected by multiple malware! If the email is very simple, the fake scan is pretty well designed. I recorded a quick video to show it to you[1]: I was late to get access to the next stage, it was already removed. We can presume that the attackers were trying to collect credentials and/or billing details. [1] https://www.youtube.com/watch?v=44XAIh2ri54 Xavier Mertens (@xme) |
Xme 697 Posts ISC Handler Jan 3rd 2022 |
Thread locked Subscribe |
Jan 3rd 2022 5 months ago |
Sign Up for Free or Log In to start participating in the conversation!