Hackers Using Morse Code in Phishing Attacks to Evade Detection

Interesting concept of old school communications; Morse Code

Microsoft has disclosed details of an evasive year-long social engineering campaign wherein the operators kept changing their obfuscation and encryption mechanisms every 37 days on average, including relying on Morse code, in an attempt to cover their tracks and surreptitiously harvest user credentials.

The phishing attacks take the form of invoice-themed lures mimicking financial-related business transactions, with the emails containing an HTML file (“XLS.HTML”). The ultimate objective is to harvest usernames and passwords, which are subsequently used as an initial entry point for later infiltration attempts.

.– — .– ……. .– …. .- – ……. .- ……. -.-. — -. -.-. . .–. – …….

Read The Full Article

Source: THN