Skip to content

At The Identity Organisation, we're here to help!

    Your privacy is important to us, and we want to communicate with you in a way which has your consent and which is in line with UK Law on data protection. As a result of a change in UK law on 25th May 2018, by providing us with your personal details you consent to us processing your data in line with current GDPR requirements.

    Here is where you can review our Privacy & GDPR Statement

    To remove consent at any time, please e-mail info@tidorg.com with the word "unsubscribe" as the subject.

    +44 (0) 1628 308038 info@tidorg.com

    Breakdown of an Impersonation Attack: Using IPFS and Personalization to Improve Attack Success

    Details from a simple impersonation phishing attack show how well thought out these attacks really are in order to heighten their ability to fool victims and harvest credentials.

    Credential harvesting scams are pretty simple at face value: send an email that links to a spoofed login page/website, and let the credentials roll on in.  But advancements in security solutions and their detection capabilities have caused attackers to evolve specific parts of an attack to make them easier to execute, easier to believe, and harder to detect.

    According to security researchers at Inky, a new ChatGPT-themed scam has been spotted that uses very specific execution worth noting that revolves around a malicious URL found within a phishing email that asks recipients to verify their email address.  The URL looks similar to the following (which has been modified and is benign):

    hxxps://bafybeidqi4sn5nfnfxlgasem4gsdmbq6m55iu6gtouomdgfwu4fx7ps7oq.ipfs[.]dweb[.]link/login.htm#b@inky.com

    There are two interesting parts to the URL, according to inky – first the use of “ipfs[.]dweb[.]link”.  The “ipfs” refers to the Interplanetary File System, a decentralized peer-to-peer file sharing network used to store and share data. By using IPFS, websites set up by attackers can’t be easily shutdown (if at all) due to the decentralized nature of the hosting.

    Second, is the mention of another domain – “@inky.com” in the example above. The domain used references a spoofed website that should be presented to convince the potential victim they are presenting credentials on a legitimate website. Assuming there are a number of possible sites ready and waiting, attackers only need to change a few characters in a malicious string and they are able to personalize an attack on yet another potential victim company.

    These attack details show how attackers are approaching the act of cyber attacks; modular kits with extensible infrastructure to ensure both availability and believability all enhance the attacker’s speed of execution and success rate.

    Your defense against such attacks is to educate users on how to respond to any unsolicited email asking for credentials (spoiler, the answer is Don’t provide credentials! – something taught in Security Awareness Training.


    The world’s largest library of security awareness training content is now just a click away!

    In your fight against phishing and social engineering you can now deploy the best-in-class simulated phishing platform combined with the world’s largest library of security awareness training content; including 1000+ interactive modules, videos, games, posters and newsletters.

    You can now get access to our new ModStore Preview Portal to see our full library of security awareness content; you can browse, search by title, category, language or content topics.

    The ModStore Preview includes:

    • Interactive training modules
    • Videos
    • Trivia Games
    • Posters and Artwork
    • Newsletters and more!

    PS: Don’t like to click on redirected buttons? Cut & Paste this link in your browser: https://info.knowbe4.com/one-on-one-demo-partners?partnerid=001a000001lWEoJAAW

    Sign Up to the TIO Intel Alerts!

    Back To Top