
9/23/2020 · Elaine Dzuba
What this post added
This post details a new phishing campaign that uses GDPR compliance as a lure to harvest credentials. It analyzes the technical aspects of the attack, including sender spoofing techniques (both visible FROM and envelope MAIL FROM), the use of Virtual Private Servers (VPS) for anonymity, and the exploitation of a compromised WordPress site for hosting the credential harvesting page. The analysis includes specific IP addresses and URLs used in the campaign, as well as the observed missteps by the attacker (e.g., Gmail account in MAIL FROM, 'Disposition-Notification-To' header) and their subsequent rectifications. It also discusses the use of SMTP HELO commands to spoof legitimate domains and bypass legacy security solutions. The post recommends employee education on phishing and the use of dedicated security solutions like Cloudflare's email security services.