Business Daily Media

Men's Weekly

.

Avanan Report: Business Email Compromise Scam Leads Credential Harvesting Evernote Page

  • Written by Jeremy Fuchs, Cybersecurity Researcher/Analyst at Avanan, A Check Point Software Company

Business Email Compromise attacks are one of the fastest-growing and most difficult-to-stop attacks in the cybersecurity space. There are a number of variants, but in general, these attacks spoof someone in your organisation, often an executive, and don’t use any malware or malicious links. (Some BEC attacks do use malware or malicious links, but the toughest ones to stop are primarily text-based.)

These attacks have led to significant financial losses, primarily because they seem real. Think about it from an end-user perspective. If you get an email from your “CEO” asking you to pay an invoice, or worse money to a customer, do you say no? That’s what hackers are hoping for.

In this BEC attack, we’ve seen hackers get even more creative. 

In this attack brief, researchers at Avanan, a Check Point Software Company, will discuss how threat actors are using the legitimacy of Evernote to help make their BEC attacks even more convincing.  

Attack

In this attack, hackers are using Evernote links to host invoices that are sent in Business Email Compromise attacks

  • Vector: Email
  • Type:  Phishing
  • Techniques: Business Email Compromise
  • Target: Any end-user

Email Example #1

This starts as an attached message, sent directly from the President of the organisation in question. This is a compromised account. Hackers will often spoof executives using trickery in the sender field; in this case, the president of the organisation was actually compromised, and thus is sent directly from that person’s account.

 

 

The attached message leads to an email saying there’s a “secure message.’ The link goes to an Evernote page. 

The Evernote page has since been taken down. But Evernote, like many legitimate websites, is being increasingly used for hacking. Recently, according to Huntress, there’s been an uptick in hosting malicious documents on Evernote.

In this case, there’s a document on Evernote that leads to a fake login page to steal credentials. 

Techniques

Business Email Compromise attacks are tough to stop from a security perspective, and tough to recognise from an end-user perspective. This attack is a hallmark of that difficulty.

It starts with an email from the President of an organisation. The account was compromised, so the email will pass all authentication measures. The message itself is not malicious. It links to a document in Evernote–not a malicious site. 

From a security perspective, this looks clean. If you’re an end-user, it looks clean. Using a legitimate site like Evernote–particuarly if Evernote is already used in that organisation–adds a ton of credence.

In short, it’s an incredibly well-crafted attack. 

Stopping BEC attacks, then, become incredibly important, and there are a few things that need to be done. For one, AI and ML need to be involved. There needs to be the ability to understand the content of an email, the context and the tone, and understanding when that differs. For example, does the President of the organisation typically send links to Evernote? 

From there, the organisation has to be able to re-write and detect malicious links and attachments. Evernote is not malicious; the document included is. Can the security service follow that link and attachment all the way through, understanding if it is indeed malicious? 

And, does the organisation have account takeover protection? We don’t know how this user was initially compromised, but today’s world provides the hacker plenty of ways to do it–email, text, voice, chat, file-sharing. Understanding login events, configuration changes and end-user activities throughout the entire productivity suite is key.

Best Practices: Guidance and Recommendations

To guard against these attacks, security professionals can do the following:

  • Create processes for employees to follow when paying invoices or entering credentials
  • Implement advanced security that looks at more than one indicator to determine in an email is clean or not
  • Utilise malicious URL detection and rewriting to follow the link to its intended destination in a safe manner

 

Online Christmas shoppers fund climate and biodiversity projects via HealthPost's Click Sphere for Good initiative

Online shoppers with HealthPost’s Flora & Fauna have made 11,000 contributions towards climate and biodiversity projects when ordering parcel ...

US landmark settlement protects SMEs, highlighting flaws in the RBA's proposed blanket card surcharging ban for Australia

Aussie SMEs warn RBA not to ignore global trends, with the current sledgehammer approach threatening business viability and increasing inflation ...

Thryv Australia named Employer of Choice for third consecutive year at Australian Business Awards

Thryv® (NASDAQ: THRY), Australia’s provider of the leading small business marketing and sales software platform, has been awarded the Employer of ...

RogersDigital.com Announces the Launch of TheBulletin.au, a Destination for Business, Policy and Financial Insight

RogersDigital.com has announced the launch of TheBulletin.au, a new national digital publication designed to deliver sharp, data-driven reporting ...

Controlling business spend is helping finance leaders to forecast with confidence

Forecasting has always been central to financial planning; however, traditional methods based on historical trends are no longer enough. Economic ...

From correction to resilience: making the most of Australia’s evolving insurance landscape

Australia is benefiting from one of the most favourable insurance market environments seen in years. However, it’s important to recognise that these...

hacklink hack forum hacklink film izle hacklink หวยออนไลน์betsmovematbetterea sigaraPusulabet Girişสล็อตเว็บตรงgamdom girişpadişahbetMostbetpradabetjojobetcarros usadospin upMostbetdizipalmatbet girişnn888trendbetbetciopusulabet girişcasibomcasibom girişcasibom giriştürk ifşaBets10pusulabetpusulabetpusulabetholiganbet色情 film izlevaycasinonakitbahisholiganbet 1178matbet güncel girişmatbet güncel girişjojobet güncel girişholiganbet girişYakabet1xbet girişjojobetGrandpashabetFİXBETbetofficeenjoybetpradabettaraftariumholiganbet girişgiftcardmall/mygiftultrabetholiganbetbets10royalbetmamibettaraftarium24casibomkingroyalbetsmoveslot spacemancasibomcasibomcasibom girişJojobetselçuksportsjustintvcasibom girişdeneme bonusumeritkingjokerbetcasibomcasibom girişpadişahbetpadişahbetyakabetSekabetBetpuantaraftariumBetnanoDinamobetultrabetVdcasinoSekabetMarsbahisgalabetultrabet girişprimebahisselçuksportsprimebahismeritkingbetcioyakabetyakabetyakabetcasibomgalabetbetkoliksahabetmr pachocasibomcasibomcolor pickervbetmeritbet girişkralbet girişultrabet girişultrabet girişultrabet girişbetnano girişcratosslot girişคลิปหลุดไทยCasibomcasibomHoliganbetdeneme bonusu veren sitelermeritbetonwinizmir escortultrabetantalya escorttimebetbahsegelultrabetultrabetultrabet girişbahiscasinobahiscasinoultrabetbets10kavbetRoyal Reelsroyal reelsultrabet 2026Kayseri Escortjojobet girişjojobetroyalbetNişantaşı EscortmilanobetmilanobetbettiltStreameastcasibom girişKalebetMavibetfixbetaviator gameÜsküdar Evden Eve Nakliyatholiganbettimebettimebettimebetbahislionistanbul escort telegramcasibombetparkpantheraproject.netcasibompusulabetholiganbet girişmarsbahisholiganbetcasibomstreameast한국야동meritkingสล็อตเว็บตรงjojobet girişholiganbet girişpornopadişahbetBetigmacasibomBetigmaBetlora girişgiftcardmall/mygiftgaziantep escorteb7png pokiesbest online casino australiabest online pokies australiareal money pokies online australiabcgame96 casinocrown155 hk casinohb88kh casinoMavibetmarsbahismarsbahisgalabetholiganbet girişjojobetcasibombets10bets10betasusholiganbetolimposcasinobetbabaholiganbet 1178holiganbet 1178olabahis girişjojobetbycasinoblooketasyabahis girişpinbahis girişbetturkeydumanbet girişjojobet girişStreameastmostbetdaftar situs judi slot gacor hb88 indonesiajojobet 1111mostbetmostbetmostbettlcasinosüratbetbahis siteleri 2025matbetcasinowon girişkavbetjojobetgiftcardmall/mygift check balance visajojobetmarsbahisซื้อหวยออนไลน์grandpashabetcasibomretcasinoasdsadasdasdasdasfdasfasfsadfasdfsdfasdasdasdasdkingroyal girişjojobetjojobetroyalbetpin up uzbekistanSlot Heart Casinomamibet logincasinomedklarna.sebetworld96 online casino cambodiaholiganbet 1178www.giftcardmall.com/mygiftwww.giftcardmall.com/mygiftcasibomtm menards loginmeybetroyalbetsekabet girişe wallet casino australiameritbetplay aristocrat pokies onlinecasibom güncel girişpusulabetmaltcasino girişjojobetcanlı maç izleklasbahisgrandpashabetsahabet