Rewterz

Rewterz Threat Alert – Protecting Your Organization from Password Spraying

July 22, 2019
Rewterz

Rewterz Threat Alert – BrushaLoader Ransomware Still Sweeping Victims

July 23, 2019

Rewterz Threat Alert – Amex Cardholders Targeted via Phishing Scheme

Severity

Medium

Analysis Summary

A new type of phishing campaign that is targeting American Express card users. In these incidents, attackers are sending a hyperlink as part of a phony account update to access the victim’s credentials and other account details.

What makes this phishing attack different is that instead of using a hyperlink to send victims to a malicious landing page, this scheme deploys an embedded “base href” URL to help hide the true intent from anti-virus and other security tools. The attackers behind this phishing campaign also sought out as many American Express users as possible and did not discriminate between corporate users or consumers. The attack targeted users four types of American Express accounts: actual credit cards, membership reward accounts, merchant accounts and American Express @Work accounts.

amexphish.jpg

Impact

  • Credential theft
  • Exposure of sensitive information

Remediation

  • Always be suspicious about emails sent by unknown senders.
  • Never click on the link/ attachments sent by unknown senders.

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.