Cyber threat actors are maliciously registering and hosting their HTTPS phishing sites with legitimate domain providing companies. This tactic is alarming because it exploits the trust of users in websites that display HTTPS certiﬁcates for the domain provider.
The HTTPS phishing campaigns continue to facilitate all types of malware delivery by cyber threat actors because victims easily trust the HTTPS certiﬁcates and click on malicious links without suspecting.
As this attack vector continues to be successful, it may result in loss or exposure of sensitive data or the destruction of IT infrastructure, leading to further exploitation and data breach.
The HTTPS phishing campaigns target ﬁnancial institutions, social media platforms, Internet service providers, courier delivery services, cloud storage, web email, online data storage, online shopping services, media service providers, and online dating sites.
Observe the following mitigation techniques to reduce the likelihood of successful HTTPS phishing attacks: