'Vishing' is latest tool of cyber criminals
Cybersecurity researchers have discovered that cybercriminals are increasingly merging 'vishing' techniques (voice phishing) with new OTP grabber services to amplify their malicious activities, a new report said on Monday.
Vishing involves manipulating individuals into revealing sensitive information over the phone.
The human touch in vishing adds a convincing element to these attacks, making victims more likely to trust the caller.
They employ sophisticated interactive voice response (IVR) systems, authentic voice recordings of real individuals, or even deploy real-time calling methods that convincingly appear to originate from a trusted company, the researchers explained.
Using such tactics, users get skillfully manipulated into revealing their one-time passwords, typically delivered via text messages.
"Employing vishing as their method of choice, the cybercriminals successfully obtained employee credentials, secured global admin privileges within Azure Tenant, exfiltrated data, and subsequently held numerous ESXi hypervisors hostage for ransom," said Shreya Talukdar, Global Threat Intelligence Analyst at CloudSEK.
The researchers recently discovered a SpoofMyAss.com (SMA) advertisement that offers the escalation of OTP bots and SMS senders that can significantly aid cybercriminals in producing large-scale vishing attacks. The features provided by SMA include OTP extraction, global calls in multiple languages, personalisation, anonymous calls, and Bot template creation, which the researchers believe strongly indicates to perform vishing attacks.
Comments
Post a Comment