New Phishing Attacks Stealing MFA Tokens Too
Summary
Targeting mostly German users, the PDF comes attached to an email with a subject line that translates from German to “Invoice for your sales tax.” Included in the email were instructions to add a certificate to the user’s trusted certificate store. This should be a red flag for anyone because Acrobat Reader can do more potentially malicious actions with a PDF than Chrome on its own, like execute JavaScript. The PDF opened an input from using Javascript that prompted us for our Amazon username and password, which we filled in with bogus information. In the meantime, the attacker in control of the phishing site would now have access to our Amazon account (if we used our real login credentials). This malware showed an evolution in typical phishing attacks, using advance techniques to gather 2FA tokens in order to access the victim’s Amazon account.