Popular file-hosting service WeChat is being exploited in the wild as attackers are using it to spread phishing campaigns. This recent discovery was made by security firm Cofense. The threat used this platform to deliver malicious URLs so that they avoid email security gateways. According to Cofense, the actors are targeting major industries such as banking, energy, and media from these campaigns.
The big picture
Worth noting
The Cofense team indicates that this new style of delivering URLs through file-hosting services was to avoid email security gateways. “As WeTransfer is a well-known and trusted file hosting system, used to share files too large to attach to an email, these links will typically bypass gateways as benign emails, unless settings are modified to restrict access to such file sharing sites,” said the researchers in their blog post.
“The PDC (Cofense team) has observed this attack method to bypass multiple gateways. These include ProofPoint, Office365 Safe Links, and Symantec,” concluded the researchers.
Publisher