🚀 لقد رفعت CloudSek جولة B1 من السلسلة B1 بقيمة 19 مليون دولار - تعزيز مستقبل الأمن السيبراني التنبؤي
اقرأ المزيد
Even though the average customer would know the domain name of their bank, this link (legitimate-site.malicious.com) could easily pass for a genuine website, fooling several users. This type of scam is known as subdomain phishing, wherein the scammer uses a legitimate subdomain along with a malicious domain name, as in legitimate-site.malicious.com. In this case, security.hsbcuk is the legitimate subdomain and confirmsecurekey.com is the suspicious domain name.
When you look up the domain name, security(.)hsbcuk(.)confirmsecurekey(.)com, on VirusTotal it points to other phishing URLs that are associated with this domain. They appear to be targeting Nationwide and HSBC customers, in particular. The URLs that are connected to the domain are:
https://request-for-new-payee(.)com/
https://security.hsbcuk.secure-key-alerts(.)com/
https://nationwide.uk.request-for-new-payee(.)com/
http://security.hsbcuk.confirm-securekey(.)com/
http://security.hsbcuk.secure-key-alerts(.)com/
http://nationwide.uk.request-for-new-payee(.)com/
http://security.hsbcuk.securekey-activity(.)com/
http://request-for-new-payee(.)com/
http://security.hsbcuk.securekey-alerts(.)com/
These phishing URLs remind us of how easy it is to obtain SSL certificates (https extension). With a much more convincing domain name and an SSL certificate, even the average user can fall prey to such attacks.
The most deceptive part of this phishing email is the hyperlink in the message (support.apple.com) that is in fact a shortened URL. And Apple customers may have been receiving emails from this sender since December 2019. Looking up this URL on VirusTotal leads to 33 other phishing URLs that may be connected to this phishing campaign.






