10/10/2024
PSA: Active and highly sophisticated social engineering attack that is targeting large organizations and users. This attack is designed to exploit trust and urgency.
How the attack unfolds:
1) Flood of Subscription Emails: The attacker uses automated scripts to sign the victim up for hundreds of email subscription services, overwhelming their inbox with legitimate "Thank you for subscribing" emails.
2) Phishing Phone Call: Posing as a member of the IT team, the attacker contacts the victim on their work phone, claiming to assist with the sudden influx of spam emails.
3) Remote Control Takeover: The attacker instructs the victim to open Quick Assist (native to Windows) or download AnyDesk to provide remote access under the guise of fixing the issue.
4) Malware Deployment: Once remote access is granted, the attacker installs malware, potentially leading to data theft and system compromise.
This type of attack preys on confusion and trust. Vigilance and quick action are key to protecting yourself and your systems.