Phishing Campaigns Use Real-Time Checks to Validate Victim Emails Before Credential Theft
Researchers studying cybersecurity are drawing attention to a novel kind of credential phishing attempt that makes sure the stolen data is linked to legitimate online accounts.
Cofense has dubbed the approach precision-validating phishing, claiming that it uses real-time email validation to ensure that the phony login screens are only shown to a limited number of high-value targets.
Since the threat actors simply interact with a pre-harvested list of legitimate email accounts, this strategy not only increases their chances of gaining useable credentials, according to the business.
In contrast to "spray-and-pray" credential harvesting attacks, which usually entail sending out large quantities of spam emails in an attempt to indiscriminately capture victims' login credentials read ...







