BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.nsec.io//YZXSDH
BEGIN:VTIMEZONE
TZID:EST
BEGIN:STANDARD
DTSTART:20001029T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10;UNTIL=20061029T070000Z
TZNAME:EST
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
END:STANDARD
BEGIN:STANDARD
DTSTART:20071104T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=11
TZNAME:EST
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000402T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=4;UNTIL=20060402T080000Z
TZNAME:EDT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
END:DAYLIGHT
BEGIN:DAYLIGHT
DTSTART:20070311T030000
RRULE:FREQ=YEARLY;BYDAY=2SU;BYMONTH=3
TZNAME:EDT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-2024-YZXSDH@cfp.nsec.io
DTSTART;TZID=EST:20240517T113000
DTEND;TZID=EST:20240517T120000
DESCRIPTION:In today's technology-driven landscape\, the transition to digi
 tal transactions has eclipsed conventional face-to-face interactions\, pre
 senting novel challenges in ensuring transaction security. Users\, perhaps
  inadvertently\, heighten security risks by opening email attachments from
  phishing attempts\, intensifying the complexities of online transaction s
 ecurity. Moreover\, there exists the potential of voluntarily disclosing s
 ensitive information\, further adding intricacy to the digital transaction
  security landscape.\n\nCompounding this issue\, cyber attacks leverage cu
 stomer data pilfered from compromised merchants. Victims find themselves c
 oerced into divulging credit card details through a sophisticated\, multi-
 step process. This research brings to light a new phishing campaign\, unra
 veling the techniques\, tactics\, procedures (TTPs)\, and indicators of co
 mpromise (IoCs) employed by threat actors. These encompass the exploitatio
 n of the platform's chat function and the incorporation of transaction dat
 a to bolster the credibility of phishing pages.\n\nThe cyber attacks\, tho
 ugh strikingly similar\, employ urgent language and intimate knowledge of 
 users' bookings\, instilling credibility in deceitful messages. However\, 
 distinctive cues like odd URLs and typos serve as saviors for potential vi
 ctims. Upon analysis\, these campaigns redirect users to counterfeit sites
  that mirror legitimate e-commerce platforms. The craftiness of cyber crim
 inals shines through identical HTML elements and scripts\, meticulously va
 lidating data and even circumventing multi-factor authentication.\n\nFurth
 er investigation unveils the tactics employed by cyber thieves: exploiting
  InfoStealer malware to breach hotel chat systems and amass valuable custo
 mer data\, escalating their targeted attacks. Open-source intelligence too
 ls reveal a broader scope\, a twin campaign where attackers impersonating 
 various platforms\, not limited to travel sites but also other e-commerce 
 platforms\, since 2021. Domain fronting is also consistently employed to c
 onceal their tracks along with some other TTPs.\n\nThe research culminates
  in insights and recommendations to enhance the security of all parties in
 volved. By implementing these suggestions\, it is hoped that both platform
 s and merchant-customers can fortify their resilience\, mitigating potenti
 al risks in the dynamic digital landscape.
DTSTAMP:20260718T025817Z
LOCATION:Salle de Bal
SUMMARY:Double Trouble: Unmasking Twin Phishing Campaigns Targeting E-comme
 rce and Travel Sites - Mangatas Tondang (@tas_kmanager)
URL:https://cfp.nsec.io/2024/talk/YZXSDH/
END:VEVENT
END:VCALENDAR
