University Students Targeted by Credential Phishing Campaign

August 12, 2021

With school starting this month, cybercriminals are back in action—targeting university students in an attempt to steal valuable personal information. In a recent attack uncovered by Abnormal, a credential phishing attacker used a legitimate email account and created false urgency to steal student credentials through a phishing website.

Summary of Attack Target

  • Platform: Google Workspace
  • Target: University Students
  • Payload: Phishing Link with Urgent Message
  • Technique: Credential Theft

About the Credential Phishing Attack

University credential phishing email 1024x685

The subject line displays a sense of urgency, with keywords including important and multiple exclamation marks. The body of the message explains that the recipient needs to update their account due to recent security incidents, and provides a link to re-secure the account. As an added threat, the text states that the account will be locked if not verified within 48 hours.

While there are some significant grammatical errors that may make a conscientious student question the legitimacy of the email, they are not so obvious that all students would recognize them. Furthermore, students in a hurry may only skim the body of the email before clicking the link to verify, and those new students who are eager to keep account access may submit their information without verifying the authenticity of the email.

Within the email, a dummy link with a variation of a address is provided, which redirects the recipient to the phishing page. In this particular attack, that redirect link was removed, and students who click on it are taken here.

University credential phishing website error 1024x633

However, those students who instead clicked on the “Click” or “URL” links in the body of the email were taken to the actual phishing website shown here.

University credential phishing payload 1024x642

This phishing page asks for not only the full name and email address of the student, but also their student ID number and their email password. Once the cybercriminal has this information, they would be able to access multiple other university services, and could potentially uncover additional personal information like addresses, financial information, and social security numbers.

Why It Bypassed Existing Security Infrastructure

Many security tools on the market are not equipped to identify suspicious behavior from a legitimate organization using legitimate email addresses. Abnormal Security prevented this attack by recognizing the specific language and content of the email, and detecting the likely compromise of the sender’s email address.

Specific signals that Abnormal noticed were the urgent language commonly observed in phishing attacks, the detection of a link that redirects the recipient to a different webpage, and the low frequency of sending behavior between the sender and recipients.

University credential phishing analysis 1024x648

In this case, Abnormal was able to detect the email within seconds and remove it from customer inboxes, ensuring that no Abnormal customer entered their credentials into the malicious website. Without this added layer of security, recipients would’ve been put at risk, and cybercriminals may have gained access to entire systems through the stolen credentials. That said, it should be noted that this exact email, as well similar attacks, may have been received by universities that do not use Abnormal Security.

While this attack was unique to a specific university and spoofed its own email domain, schools everywhere should be aware of this tactic and seek to prevent it, particularly as students return this August.

Interested in seeing how Abnormal can prevent credential phishing at your organization? See the product in action by requesting a demo.

Blog yellow ransomware screen
On August 12, 2021, we identified and blocked a number of emails sent to Abnormal Security customers soliciting them to become accomplices in an insider threat scheme. The goal was for them to infect their companies’ networks with ransomware. These emails allege to come from someone with ties to the DemonWare ransomware group.
Read More
Blog green computer
Phishing is the most common form of cyberattack in the world. Approximately 74% of organizations within the United States will experience a successful phishing attack at some point. Spear phishing, on the other hand, is a more targeted form of a phishing attack and is far more sinister.
Read More

Related Posts

B 10 15 21
With Detection 360, submission to threat containment just got 94% faster, making it incredibly easy for customers to submit false positives or missed attacks, and get real-time updates from Abnormal on investigation, conclusion, and remediation.
Read More
Extortion blog cover
Unfortunately, physically threatening extortion attempts sent via email continue to impact companies and public institutions when received—disrupting business, intimidating employees, and occasioning costly responses from public safety.
Read More
Blog engineering cybersecurity careers
Cybersecurity Careers Awareness Week is a great opportunity to explore key careers in information security, particularly as there are an estimated 3.1 million unfilled cybersecurity jobs. This disparity means that cybercriminals are taking advantage of the situation, sending more targeted attacks and seeing greater success each year.
Read More
Blog hiring cybersecurity leaders
As with every equation, there are always two sides and while it can be easy to blame users when they fall victim to scams and attacks, we also need to examine how we build and staff security teams.
Read More
Cover automated ato
With an increase in threat actor attention toward compromising accounts, Abnormal is focused on protecting our customers from this potentially high-profile threat. We are pleased to announce that our new Automated Account Takeover (ATO) Remediation functionality is available.
Read More
Email spoofing cover
Email spoofing is a common form of phishing attack designed to make the recipient believe that the message originates from a trusted source. A spoofed email is more than just a nuisance—it’s a malicious communication that poses a significant security threat.
Read More
Cover cybersecurity month kickoff
It’s time to turn the page on the calendar, and we are finally in October—the one month of the year when the spooky becomes reality. October is a unique juncture in the year as most companies are making the mad dash to year-end...
Read More
Ices announcement cover
Abnormal ICES offers all-in-one email security, delivering a precise approach to combat the full spectrum of email-borne threats. Powered by behavioral AI technology and deeply integrated with Microsoft 365...
Read More
Account takeover cover
Account takeovers are one of the biggest threats facing organizations of all sizes. They happen when cybercriminals gain legitimate login credentials and then use those credentials to send more attacks, acting like the person...
Read More
Blog podcast green cover
Many companies aspire to be customer-centric, but few find a way to operationalize customer-centricity into their team’s culture. As a 3x SaaS startup founder, most recently at Orum, and a veteran of Facebook and Palantir, Ayush Sood...
Read More
Blog attack atlassian cover
Credential phishing links are most commonly sent by email, and they typically lead to a website that is designed to look like common applications—most notably Microsoft Office 365, Google, Amazon, or other well-known...
Read More
Blog podcast purple cover
Working at hyper-growth startups usually means that unreasonable expectations will be thrust on individuals and teams. Demanding timelines, goals, and expectations can lead to high pressure, stress, accountability, and ultimately, extraordinary growth and achievements.
Read More