{"id":5171,"date":"2024-09-05T15:56:45","date_gmt":"2024-09-05T20:56:45","guid":{"rendered":"https:\/\/www.darkreading.com\/threat-intelligence\/malvertising-campaign-phish-lowes-employees"},"modified":"2024-09-05T15:56:45","modified_gmt":"2024-09-05T20:56:45","slug":"malvertising-campaign-builds-a-phish-for-lowes-employees","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/09\/05\/malvertising-campaign-builds-a-phish-for-lowes-employees\/","title":{"rendered":"Malvertising Campaign Builds a Phish for Lowe&#8217;s Employees"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt5399e2d0741c93be\/66da06a892d0376db0ad937b\/Lowes-Betty_LaRue-Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/malvertising-campaign-builds-a-phish-for-lowes-employees.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/malvertising-campaign-builds-a-phish-for-lowes-employees.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Lowe&#8217;s employees are being phished for their credentials via sponsored Google ads.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Midway last month, J\u00e9r\u00f4me Segura, senior director of research at Malwarebytes, came across a small group of <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2024\/09\/lowes-employees-phished-via-google-ads\" rel=\"noopener\">malicious websites mimicking MyLowesLife<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, the hundred-plus-billion-dollar company&#8217;s employee portal for all things scheduling, pay stubs, etc. The typosquatting domains mimicked the exact structure of the real MyLowesLife, and were sponsored aggressively in Google searches. In one case, when researchers searched for &#8220;myloweslife,&#8221; the top three results were sponsored ads associated with the malicious campaign.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Lowe&#8217;s employees who followed these links would find few reasons to be suspicious of what they found. The resultant landing page mimicked the real Lowe&#8217;s employee portal to the tee, with fields for users to submit their sales (account) numbers and passwords. Those who hit &#8216;Login&#8217; were then asked for their &#8220;Answer to you<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_italic\">[sic] <\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">security question.&#8221; All three items of data would then be forwarded to an attacker-controlled phishing kit.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Stolen credentials give a threat actor access to very valuable information that could be used for identity theft,&#8221; Segura warns. &#8220;Impacted Lowe&#8217;s employees could be defrauded and suffer monetary losses. In a successful run, several dozen employee accounts could translate into theft related to their benefits or banking details.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Notably, the main homepages for these copycat sites \u2014 myloveslife[.]net, mylifelowes[.]org, mylifelowes[.]net, and myliveloves[.]net \u2014 were populated by entirely generic, apparently AI-generated templates for retail websites, having nothing to do with Lowe&#8217;s whatsoever. As Segura explains, this is entirely strategic. Besides saving the threat actor time and effort, having an innocuous homepage could throw off investigators, and make the case for taking down these sites with their domain registrar more difficult.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Why Malvertisements Work\">Why Malvertisements Work<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;It&#8217;s often just quicker and easier to reach the website you&#8217;re looking for through a quick search, instead of typing a full domain into your browser.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">There&#8217;s also a trust factor built into mainstream search engines, whose algorithms are built to promote safe, reliable results towards the top of any given search. Sponsored results don&#8217;t earn their real estate on merit, but casual Internet surfers might unthinkingly afford them the same level of trust nonetheless.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">These reasons, among others, help explain the general popularity of malvertising as a means of stealing credentials and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/endpoint-security\/google-searches-usps-tracking-banking-theft\" rel=\"noopener\">infecting targeted demographics with malware<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, and why <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/-nitrogen-ransomware-effort-lures-it-pros-via-google-bing-ads\" rel=\"noopener\">even technically savvy Internet users<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> have been falling victim to recent campaigns. In only the last few months, for example, Malwarebytes has tracked different scams targeting IT staff, tech-forward early adopters of the Arc browser, and more.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The case involving Lowe&#8217;s employees is unique since, unlike IT tools and new browsers, it doesn&#8217;t make logical sense to advertise an internal company portal to the public. In theory, this should make these fake ads easier to spot, both for Web surfers and search providers.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Google and other search engines could prevent such phishing campaigns by monitoring benefit portals, Single Sign On (SSO) pages, etc. that an &#8216;advertiser&#8217; is purchasing ad space for. In fact, we use the same technique to hunt and find those malicious ads, so I believe it could be used to proactively ban accounts before they have a chance to lure in victims,&#8221; Segura thinks.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/malvertising-campaign-phish-lowes-employees\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Lowe&#8217;s employees are being phished for their credentials via sponsored<\/p>\n","protected":false},"author":12,"featured_media":5172,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-5171","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/malvertising-campaign-builds-a-phish-for-lowes-employees-scaled.jpg?fit=2560%2C1440&ssl=1",2560,1440,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/malvertising-campaign-builds-a-phish-for-lowes-employees-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/malvertising-campaign-builds-a-phish-for-lowes-employees-scaled.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/malvertising-campaign-builds-a-phish-for-lowes-employees-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/malvertising-campaign-builds-a-phish-for-lowes-employees-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/malvertising-campaign-builds-a-phish-for-lowes-employees-scaled.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/malvertising-campaign-builds-a-phish-for-lowes-employees-scaled.jpg?fit=2048%2C1152&ssl=1",2048,1152,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/malvertising-campaign-builds-a-phish-for-lowes-employees-scaled.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/malvertising-campaign-builds-a-phish-for-lowes-employees-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/malvertising-campaign-builds-a-phish-for-lowes-employees-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/malvertising-campaign-builds-a-phish-for-lowes-employees-scaled.jpg?fit=2560%2C1440&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5171","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=5171"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5171\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/5172"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=5171"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=5171"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=5171"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}