YouTube attribution links exploited in new phishing campaign

Cybersecurity company Vade said the use of YouTube attribution links was a new tactic for bypassing email filters scanning for suspicious redirects.

In a newly discovered phishing campaign, victims receive a spoofed email saying their Microsoft 365 password has expired. The email is personalized and contextualized to create an illusion of legitimacy.

Vade researchers noted that the email doesn’t contain misspellings or grammatical errors, which used to be a first telltale sign of a scam.

Below the notice of the allegedly expired password, there’s an option for the victim to keep their current password. The button, hyperlinked to a YouTube URL eventually redirects users to a phishing page read more YouTube attribution links exploited in new phishing campaign.

With ReconBee.com Stay ahead of the latest threats with in-depth coverage of cyber attacks and cybersecurity trends, and the latest cybersecurity news.

Leave a Reply

Your email address will not be published. Required fields are marked *