Categories: Ad Guardian PlusNews

WeTransfer Used in Malicious Spam Campaigns

Hackers abuse WeTransfer, the popular file-sharing service, to circumvent the defensive email gateways that should block spam messages with malicious URLs, according to Threat Post. The problem appears when the transfered file is an HTM or HTML file redirecting to a phishing landing pageIn order to abuse the service, a user inputs a “from” email address and a recipient email address and uploads a file. Then, the sender can customize a message that the recipient sees.

Jake Longden, a threat analyst for Cofense – a provider of human-driven phishing defense solutions worldwide, wrote that: ”The email body is a geniune notification from WeTransfer, which informs the victim that a file has been shared with them. The threat actor often writes a note stating that the file is an invoice. When the user clicks on the ’Get your files’ button in the message body, the user is redirected where the HTM or HTML file is hosted and thus downloaded by the unsuspecting victim. When the user opens the .html file, he or she is redirected to the main phishing page.

Then, the attack continues with victims asked to enter their Office365 credentials, in order to login and retrieve the file. The researcher added, recent campaigns have targeted Microsoft Services, but other brands have also been spoofed.

WeTransfer did not return the requests to comment for this article.

Laurentiu Titei

View Comments

Recent Posts

How to Update Windows Security Signatures Manually Windows 11/10

Windows Security signatures are digital fingerprints that verify the integrity and authenticity of various software…

1 day ago

How to Encrypt and Secure an Email in Outlook

Microsoft Outlook is among the most popular professional email management, calendar, and scheduling, contact management,…

2 days ago

What Is an OFX File and How to Open it on a Windows PC

Do you need to open an OFX file to import your bank statements and transactions…

2 days ago

Easy Ways to Solve Error Code 1603 (Fatal Error During Installation)

Are you unable to install software or updates, such as Java or Autodesk products, because…

3 days ago

Best Methods to Disable Ad Blocker in Windows 10 and 11

Do you know that specific websites and content creators make money through you without directly…

3 days ago

How to Restore Passwords Saved to this Computer

Out of all things we can forget, from phone numbers to passwords, forgetting a password…

4 days ago