January 9, 2019 By David Bisson < 1 min read

A new phishing kit uses a custom web font to implement a substitution cipher in its efforts to target customers of a major U.S. bank.

Researchers at Proofpoint first came across the unnamed phishing kit in May 2018. The landing page leverages stolen branding to steal users’ credentials for a major retail bank, and the source code includes encoded display text.

Digging further, the researchers determined that the base64-encoded woff and woff2 files were the only loaded fonts in the template. They then observed that the kit uses a custom web font file to render the ciphertext as plaintext, which helps it evade detection and conceals its activity from victims.

A Busy Year for Phishing Kits

Phishing kits were a prominent threat in 2018. Check Point came across a new phishing kit on the dark web in April 2018. The template provided would-be criminals with a backend interface for creating convincing fake retail product pages and managing their entire campaign. A few months later, Akamai analyzed a zip file containing phishing kits. One of the five directories analyzed by Akamai had code to target a bank located in the Southern and Midwestern states.

Several new malicious document builders have also emerged over the past two years. In October 2017, Proofpoint discovered ThreadKit, a Microsoft Office document exploit builder kit used for distributing Formbook, Loki Bot and other malware. Just a few months later, the security firm came across LCG Kit, another weaponized document builder service.

How to Defend Against Phishing Attacks

Security professionals can help defend their organizations against phishing attacks by proactively running phishing simulations to test their employees’ security awareness. They should also conduct penetration tests to analyze other aspects of their organizations’ email security.

More from

When ransomware kills: Attacks on healthcare facilities

4 min read - As ransomware attacks continue to escalate, their toll is often measured in data loss and financial strain. But what about the loss of human life? Nowhere is the ransomware threat more acute than in the healthcare sector, where patients’ lives are literally on the line.Since 2015, there has been a staggering increase in ransomware attacks on healthcare facilities. And the impacts are severe: Diverted emergency services, delayed critical treatments and even fatalities. Meanwhile, the pledge some ransomware groups made during…

AI and cloud vulnerabilities aren’t the only threats facing CISOs today

6 min read - With cloud infrastructure and, more recently, artificial intelligence (AI) systems becoming prime targets for attackers, security leaders are laser-focused on defending these high-profile areas. They’re right to do so, too, as cyber criminals turn to new and emerging technologies to launch and scale ever more sophisticated attacks.However, this heightened attention to emerging threats makes it easy to overlook traditional attack vectors, such as human-driven social engineering and vulnerabilities in physical security.As adversaries exploit an ever-wider range of potential entry points…

4 trends in software supply chain security

4 min read - Some of the biggest and most infamous cyberattacks of the past decade were caused by a security breakdown in the software supply chain. SolarWinds was probably the most well-known, but it was not alone. Incidents against companies like Equifax and tools like MOVEit also wreaked havoc for organizations and customers whose sensitive information was compromised.Expect to see more software supply chain attacks moving forward. According to ReversingLabs' The State of Software Supply Chain Security 2024 study, attacks against the software…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today