SUCURILABS
SUCURILABS
BlogAbout us

Threat Insights 0x2E: Banking on Fear

November 16, 2024

Fake Bank Security Alerts

Email 1

  • Rating: ★★★☆☆
  • Date: 2024-11-16
  • Objective: Credential harvesting
  • Analyst: José Morim

Several phishing emails pretended to be urgent security alerts from well-known banks, warning recipients of unauthorized access or account restrictions. These emails included links that directed users to phishing pages designed to capture login credentials.

Page 1

Victims who entered their credentials saw a generic "security review in progress" message, while their data was sent straight to the attackers.

Fraudulent Email Verification Notices

Email 2

  • Rating: ★★☆☆☆
  • Date: 2024-11-14
  • Objective: Credential harvesting
  • Analyst: José Morim

This phishing attempt impersonates a popular email provider, alerting users that their inbox requires urgent verification. The email contains a convincing "Verify Now" button.

Page 2

Clicking it takes users to a fake login page, designed to look identical to the real email provider's login portal. Once credentials are entered, the attacker gains full access to the victim’s email account.

Fake Loan Approval Scam

Email 3

  • Rating: ★★☆☆☆
  • Date: 2024-11-13
  • Objective: Credential harvesting
  • Analyst: José Morim

This phishing email lures victims by claiming they have been pre-approved for a large loan with attractive terms. It urges recipients to click a link to "finalize their approval."

Page 3

Instead of leading to a bank’s official site, the link takes users to a fraudulent financial portal that requests personal information, including Social Security numbers and banking details.

Indicators of Compromise

TYPEIOC
URLhxxps[://]securelogin[.]net/bank-update
URLhxxps[://]emailverify[.]co/verification
URLhxxps[://]quickloanapproval[.]info
FILE5e7baf4b3d94cf126b3e2e9c8370a1b5d4e2fd8f9214f3e556c9a2e7f5a3b4e6
FILE97c1d3a6b5e4fd8a2f5c3b7e9d126b4e2fd8f5a3b4e6c9a2e7f5a3b4e6d1c2b7

Keep up with Threat Insights

Threat Insights is a weekly series where we present you with analysis from samples we collect. Follow us on social media for the latest feed and cybersecurity content. Stay informed and stay safe!


Get more insights like this

  • Follow us on social media to get a weekly update of our latest content, and don't worry—we won't spam your feed ;)
  • Join our private beta and have a sneak peek at how your team will improve their security posture.


Copyright © 2024-2025 SUCURILABS Lda. All rights reserved.