Skip to main content

Suspicious teaser: Kaspersky warns that scammers hide phishing links behind images

19 September 2024

At the end of August, Kaspersky experts discovered a phishing campaign with an unusual attack vector – through an image. This scam targeted organisations in the fields of online retail, distribution, transportation, and logistics. The cyber attackers aimed to steal corporate email credentials from potential victims.

Within the phishing scheme, the cyber attackers send emails in English, allegedly on behalf of a South Korean company. Pretending to be employees of this organisation, the cybercriminals email about sending instructions to their bank for transferring a payment. They ask potential victims to check the details in the scanned document, which is added to the body of the letter. According to the legend, this must be done quickly in order to receive payment as soon as possible.

Phishing e-mail with image

Phishing email with the image

"The image in these phishing emails is poorly visible – this is what the attackers are counting on. Even if a person does not expect an email, he may be interested in looking at the details. However, in reality, the image hides a phishing link. If the users click on the scan, they will be redirected to a fake resource that mimics a file sharing service from Adobe. There, they will be asked to enter the credentials for a corporate email account to gain access to the document. However, this should never be done, otherwise this information will go to the cybercriminals," comments Roman Dedenok, a cybersecurity expert at Kaspersky.

To avoid becoming a victim of such phishing attacks, Kaspersky recommends that users do not trust emails from unknown mailboxes, especially when it comes to confidential data, financial transactions and suspicious attachments, even if it visually looks like the email came from an organisation with a good reputation. Kaspersky also recommends that companies install a reliable security solution that will automatically send such emails to spam, such as Kaspersky Secure Mail Gateway, and also regularly conduct cybersecurity training for employees, teaching them how to recognise social engineering techniques, for example, using the Kaspersky Automated Security Awareness Platform.

Suspicious teaser: Kaspersky warns that scammers hide phishing links behind images

At the end of August, Kaspersky experts discovered a phishing campaign with an unusual attack vector – through an image. This scam targeted organisations in the fields of online retail, distribution, transportation, and logistics. The cyber attackers aimed to steal corporate email credentials from potential victims.
Kaspersky logo

About Kaspersky

Kaspersky is a global cybersecurity and digital privacy company founded in 1997. Innovating the industry with a Cyber Immunity approach, Kaspersky safeguards consumers, businesses, critical infrastructure, and governments from cyberthreats, with over a billion devices protected to date.

Kaspersky ensures Cybersecurity True to Business, focusing on providing clear outcomes, protecting revenue, easing workloads and preventing downtime. Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services for organizations of every size, from small businesses to large enterprises, combining proven AI-driven protection technologies with simple management and expert support.

Recognized in independent tests and trusted by millions of individuals worldwide and nearly 200,000 organizations, Kaspersky helps detect threats earlier, respond faster and operate with greater confidence and freedom, protecting what matters most to our clients. Learn more at www.kaspersky.com.

Related Articles Press Releases