Kaspersky Daily: reported:
The attack employed a multi-stage approach — before sending the phishing link directly, the attackers engaged in correspondence with the victim to lower their guard. The email texts were apparently generated using large language models.
The attackers attempt to pose as potential clients. The emails are sent from addresses registered on free email services.
If someone responds to the first email, the attackers continue the correspondence. Sometimes, before moving directly to their objective — extracting credentials from corporate email accounts — they exchange several messages in which, as a distraction, they clarify certain details or ask additional questions. But more often than not, they send the phishing link as early as the second email.
The attackers attempt to pose as potential clients. The emails are sent from addresses registered on free email services.
If someone responds to the first email, the attackers continue the correspondence. Sometimes, before moving directly to their objective — extracting credentials from corporate email accounts — they exchange several messages in which, as a distraction, they clarify certain details or ask additional questions. But more often than not, they send the phishing link as early as the second email.
Find the original article here.
Key Takeaway: Don't click on links within an email. Access the site from a previous bookmark or password manager.
Enroll in Training Sessions: Last Thursday of Every Month is Training on Frauds and New Scam Alerts and How to Combat
Enroll in Training Sessions: Last Thursday of Every Month is Training on Frauds and New Scam Alerts and How to Combat
