Rewterz Threat Advisory – CVE-2020-15679 – Mozilla VPN session hijacking
November 6, 2020Rewterz Threat Advisory – ICS:Mitsubishi Electric GT14 Model of GOT1000 Series
November 6, 2020Rewterz Threat Advisory – CVE-2020-15679 – Mozilla VPN session hijacking
November 6, 2020Rewterz Threat Advisory – ICS:Mitsubishi Electric GT14 Model of GOT1000 Series
November 6, 2020Severity
Medium
Analysis Summary
Researchers have discovered a campaign targeting financial data from companies. The email is relatively simple but customized towards the target. The display name is spoofed to appear to come from an executive at a global financial firm. The sender and Reply-To header appear to be associated with a legitimate law firm, likely comprised by the attackers in order to increase legitimacy and evade detection. The body of the email targets the recipient directly with their first name contained in the introduction. Various financial details are then urgently requested. If a recipient falls victim and provides the information, the attackers can leverage it for financial fraud.
Impact
- Credential theft
- Exposure of sensitive data
Indicators of Compromise
Email Subject
Please get this information
Remediation
- Block all threat indicators at your respective controls.
- Always be suspicious about emails sent by unknown senders.
- Never click on links/attachments sent by unknown senders.