Phishing Attempts Against IPVM Employees - Any Insights?

Avatar
Donald Maye
Nov 16, 2021

To help make others aware of phishing tactics, I want to share details of a recent attempt against an IPVM employee. Also, in event there are those who have expertise or insight into how common various phishing tactics are- it would be good to hear what you think.

In the below examples, a sender, using a Gmail account, is pretending to be John Honovich – using his name and title (in one attempt), to approach an IPVM employee.

IPVM Image

IPVM Image

IPVM Image

**** ****** *** ** *** ******** these ******** ******* ***:

** *** ****** **** ***** – we've **** **** **** ****** ** IPVM- ***** **** ** ******** ** the ****, ** *** ******** ******* their ********, **** *** ********** **** a ******** *******.

**** ****** **** *** ******* *********** or ********** *******?

(3)
Avatar
Brian Karas
Nov 16, 2021
Pelican Zero

**** ****** **** *** ******* *********** or ********** *******?

**** ** ***** ******, ****. * don't ***** ***** ** *** ******** targeting ** **** ** ********* ****.

(1)
JH
John Honovich
Nov 16, 2021
IPVM

**'* ********* ****? **'* ****** *** it **** ***** ********? *** ********?

Avatar
Brian Karas
Nov 16, 2021
Pelican Zero

** **** **** ** ** ****** automated, ***** * ****** *** ** human ********. *'** ****** ****, *** Angela *** **** ******** ****, *** had *** ****/***** **** ** *** "from" ***** ** **** **** ** her *********. ** *** ****, *** phishers ********** * ****** **** *** very ***** ** ***** ******* ******, but ** **** * *** **** it ***** **** **** **** *** result ** **** ***** **********.

******* ******** **** ********* *** ******** telling ** **** **** ** ***** new **** ******* *** ** ****** employees **** *** ********** ** *** company ***** *** ** **** **** email *** ********* ****** **** ** purchase ***** **** ***** ** ***** items *** ********* ******* *****. * think ***** ********* ******** ****** *** very **********.

(1)
(2)
(1)
Avatar
Clint Hays
Nov 16, 2021

* *** * ******* ***** **** so * ***'* ***** ** ** anything ******* ******* ****.

(1)
U
Undisclosed #1
Nov 16, 2021
IPVMU Certified

**** ** **** **** ***** ******…

*** * ****** *****. *** **** they ****.

(1)
(1)
(3)
AM
Andrew Myers
Nov 16, 2021

(1)
AM
Andrew Myers
Nov 16, 2021

*** **** ** *** * ***** for **,

**** **** ** ******,

**** ******* *****, ********* ***** ***** addresses... ** ***** ****** *** ******. There**** **** *************** ******** ******* **** ***** ************* to **** *** *** **** ******** targets (*'* *** **** **** ******** makes *****). ******** *** *** ************ targeting *** ***** ******** **** ** with ********* **** **** **********.

UM
Undisclosed Manufacturer #2
Nov 16, 2021

* *** *** ** ***** **** was ********** **** * **-******. * saw **** ** *** *** **** my *******'* ***** ******* *** *** to **** ************* ** *** **** it *** ********* **** ** ***** might **** **** * **-******'* ******** email *******. * **** ** **** phone ******. * **** *** * text ****** **** *** *** * meeting **** ** ********* ****** *** could * ******** **** **** ***** that ** ***** **** ** ***** clients. ** **** ***** * **** right **** **** *** ********* *** deleted *** **** *** ******* *** number.

(2)
U
Undisclosed #3
Nov 16, 2021

**** ***** ******** ** ********* ***** on ******* ** *** ********** ******* the ****** *** *** ******** ******* I *******.

**’* * ****** *** ******* ****** with **** *************** ** ****** **’* automated, ** ********’* ********* *** *** they’re ***** *** ***’* **** ** pony ** *** * ******* ******** campaign :)

(1)
UI
Undisclosed Integrator #4
Nov 16, 2021

** *** *** **** ******** **** this ******; *** ****** ** ****** always *** **** ***. *** **** invoice, ***** **** ****, *** ** some ****** *********, *** *** ***.

(1)
AG
Alex Gruss
Nov 16, 2021

* *** **** ***** **** ** own *********** ****** ** *****.

** ***** ** ****** *** ******** spear ******** *******. **** ** ***** spoofers *** **** ******* ********* *** they ****** ******** ****** ********** *******, which ** *** ** ***** ********* and *** *** *******. **** **** websites *** *********** *** ****** *** employees **** *** **** **** ****'* who **** ******* ** **. **** may ** ****** *********.

**** *** *** *** **** ** that **% ** *** ******* ********** are ********. ****** *****-******** **** ****, or ******** (**** ********). * ****** IPVM ** ****** **** **** ********** a ******** **** ** *** ***, and *** ** ** * ****** to ******* ***** *** ***** *** fooled. ** *** **** **** *** its * ****** ******* **** **** cost **** **** **** ******* ******** will.

** *** **** * **** ******, try ****** *** ****** *****. **** of ***** ******** ** *** **** DMARC ** **** (******** *** ************ of ** ***** *******) ******* *** that **** **** *** ******.

***** *** **** ** ****** ********* but * **** ******* ********* ** answer *** ********* *** ***** *** need **** **** **** ******* ** network ********.

(2)
(3)
JH
John Honovich
Nov 16, 2021
IPVM

****** ***! * *** ********* ***** phishing ******** ******* **** **** / train ********* **** "****" ******** ********. What ** *** ***** ** *****? and ** ** *** ******** **** you *********?

AG
Alex Gruss
Nov 16, 2021

**'** **** **** **** *** ***. One ******* ***********, ***** *** **** **** ** setup *** *** *******- * ** person **** ***** ************** ********** ***** easily ******* *** *** *** *** results. *** *** *** * *** tests *** **** ***** ***** ******* the *****.

** **************** ** * ****** **** ******** but ** **** **** ************ *** completely ****!

(4)
(1)
(1)
JH
John Honovich
Nov 16, 2021
IPVM

****** *** ******* ***** *******, *******! I've ***** ***** *** ****** *** may ** ********** ** ****.

U
Undisclosed #5
Nov 16, 2021

Avatar
Brian Karas
Nov 16, 2021
Pelican Zero

***'** **** ******** **.

***** *** ****** **** ** **** to ****** **** * ****** *** of ******** *********.

*** *** **** ** ********* **** I ***** *** **** ** ****, just **** ** * ****** ******* to **** *** * ******** *****.

(1)
Avatar
Hans Kahler
Nov 17, 2021
Eagle Eye Networks

** *** **** **** **** ** thing. ** ******** ***** *** ********* on *** *** *** **** ******** type ** ******* (*** ******.). ** have ******** ******* ** * ****** to *** **** *******. *********** **** want *** *** ******** ** ** buy **** ***** (****** ** *****) and **** **** ****** ** **** to *** ********. * **** * couple ** ******* **** ***** ********** that **** *** ******* *********.

IJ
Ian Johnston
Nov 17, 2021

*** **** **** ****** *** ******** you *** **** **** **** ******* to *****?

(1)
UI
Undisclosed Integrator #6
Nov 17, 2021

*** ****** ********!

Avatar
Marty Major
Nov 17, 2021
Teledyne FLIR

** *** **** *** *** ******* company, **** ** **** (** * vendor **** ****) **** ********* *** your ***** **** ***** **** ******** emails.

***'** ******** ** ***** ** *** Phish **** *** ******* **** *** think **'* * ******** ***** *** then **** *** ** * ************** message *** *** ***** * ***** and *** *** *** ** **** anyone ***** *** ******** ** **** they *** ******.

* *** *** **** ** **, but ********** * **** **** ***** annoying *** **** **** **** ** the *****.

(1)
(1)
U
Undisclosed #1
Nov 17, 2021
IPVMU Certified

…**** ***** **** ******** ******.

** ****’** **********?

…*** *** *** ** **** ****** about *** ******** ** **** **** are ******.

*** ******’* **** **** *** ** tell? ***’* **** **** **** ** raise *********?

(1)
(1)
(1)
Avatar
Marty Major
Nov 17, 2021
Teledyne FLIR

*** ******’* **** **** *** ** tell? ***’* **** **** **** ** raise *********?

***** **********'* **** ****** - **** **'* our ****** ****** - *** ******* that ** **** **** ** *** to **** * **** *** ** able ** ****** *** **** ** tell ******* * ****** **** * know **** **** ***'*.

** *********** **** *** **** ****** to *** ** ** ** ********* pawn ** ***** ********* ********.

U
Undisclosed #1
Nov 18, 2021
IPVMU Certified

…*** [ **** ] ******* **** if **** **** ** *** ** tell * **** *** ** **** to ****** *** **** ** **** someone * ******…

***’* *** ******* ********** ****** ***.

***’* *** ******* ********** ****** ***.

***’* *** ******* ********** ****** ***.

(1)
(1)
(1)
Avatar
Marty Major
Nov 18, 2021
Teledyne FLIR

******, ***...

******* ********** ** *** ** *** weakest *** *******-**-**** ***** ** **********/**** flam - *** *****'* **** **** on ***** **** ** **** *** naturally ********** ** **********.

U
Undisclosed #1
Nov 18, 2021
IPVMU Certified

******, ***...

*** ** ********** *’* ******, *****?

“***’*…”

(1)
(1)
(1)
Avatar
Marty Major
Nov 18, 2021
Teledyne FLIR

* **** *** ***** **** ** your *****... ***** **%. ; )

UI
Undisclosed Integrator #7
Nov 18, 2021

**** ** **** **** **** *******...

**** *** ****, *** ******* ****.

Avatar
Lynn Harold
Nov 18, 2021

*'** ***** *** ****** ** ******* based ** *** ******* .... "*** * ***** *** **".

UM
Undisclosed Manufacturer #8
Nov 22, 2021

* *** *** **** ***** **** of ****** ** * ******* ***** as ** ****** ****** *** ************.

UE
Undisclosed End User #9
Nov 22, 2021

* ******'* *********** **** ** *** "foreign, ******* ****" ***** *** ********* this ********. **'* ******, ****, *** I've **** **** ****** *** ***** with ******* ******* *** ****** ** a **** ** *****. * ***'* even **** **** ** ***** ****** in **** **** *** ********, ** I **** ***** *******. ******** * get ** ***** ********** * ********, I ***** *** ****** *****. ****'* usually * ****** **** ****.

UM
Undisclosed Manufacturer #10
Nov 23, 2021

Top ********:

*. *********

*. *****

*. ***** ********

/ **

(3)
JH
John Honovich
Aug 14, 2022
IPVM

******:******* **** ********** ********* ** **** ***** **** messaging:

*** **** ***** **** ******* ****** Morning **** ** * *******, ** received *** ********* ****: “***** ****, I’m ** * ********** ***** ***, can’t **** ** *** ***** *** let ** **** ** *** *** my ****. ******.” ** *** ****** “Austin ****” ***, ** **** *** didn’t ****, **’* *** *** ** Morning ****.

******* ****’* *** **** ******* **** employee ** *** *** ****—****** **** reported ********* ******* ****. ** ******* responded ** *** ****, *** ****** would ******* *** *** **** *****, promising ** *** **** **** *****. The ***** *****’* ******** **** ****. Morning ****, **** ** **** ********** across *** *******, *** **** * victim ** * ******** ****. (**** eventually **** * *********** ***** ******* letting ******** ********** **** **** ** wasn’t ********* ****** *** ********* *** gift ***** ** ****.)

* *********** ** *** *** ********, smishing **** ********** **** ******** ** trick ********** **** ******* ***** ** personal ***********.

**’* *** **** ******* ****: *** numbers ** ******** ********* *** ****** are **********. *********** ********** ****** **** ******** ******* more **** ******* ** *** ** in ****. **** **** *** ******* Trade ********** (***)********* ***,*** ***** ******* **** ***** in **** ********* **** ********. ** those ********* ** *******, ********* **** a ***** ** $*** ******* ** smishing ***** **** * ****** **** of $***. (**** ***** ** ********** to *** ***.)

New discussion

Ask questions and get answers to your physical security questions from IPVM team members and fellow subscribers.

Newest discussions