3、钓鱼攻击活动伪装用户联系人欺骗Gmail用户
标题:This Phishing Scam Is Targeting Gmail Accounts by Posing as Your Contacts
作者信息:January 14, 2017 5:00am By Jay Serafino
//BEGIN
You might think you're tech-savvy enough to spot a fake email from a scammer pretending to be PayPal or eBay, but what about one coming from a familiar contact? And what if the message attached read just like something sent from a real person? That's exactly what a new email phishing scam is doing to unassuming Gmail users, according to Boing Boing.
如果您认为自己已经具备了一双识别钓鱼邮件的慧眼啦,那么建议您还是读读这篇文章先。
钓鱼邮件已经不满足与冒充PayPal或者eBay等的支付邮件了,现在他们冒充您通讯录里的人,而且其邮件标题以及附件看起来很像是您原来就发送过的,但是正文的URL才是鱼饵所在!点击这个URL就能登录到一个假冒的Gmail邮件登录页面。如果您不经常登录Gmail或者不熟悉其具体流程,慌张中很可能就将自己的登陆账号和密码拱手相送给黑客了。
//END
The attackers log in to your account immediately once they get the credentials, and they use one of your actual attachments, along with one of your actual subject lines, and send it to people in your contact list.
For example, they went into one student’s account, pulled an attachment with an athletic team practice schedule, generated the screenshot, and then paired that with a subject line that was tangentially related, and emailed it to the other members of the athletic team.”
一旦您输入了自己的登录账号信息,那么黑客就会很快真的会登录到您的信箱中,然后进一步采用类似的方法进行下一步的钓鱼行动,这就是所谓的“链式”效应吧:下一个位于您邮箱中的联系人以及往来的信件(含附件)就会再次被利用、传播:真实的邮件附件、真实的邮件主题、发送到联系人信箱。
点评:假作真时真亦假。真真假假。 |