Last Updated: 2021-03-11 03:06:23 UTC
by Johannes Ullrich (Version: 1)
[This is a guest diary submitted by JB Bowers]
In line with our recent diaries featuring unique attack vectors for credential theft, such as phishing over LinkedIn Mail and pretending to be an Outlook version update, we've recently learned of a phishing campaign targetting users of the Infographic service Piktochart.
During the COVID-19 pandemic, nearly every kind of company has moved to use more online collaboration tools. This means that many small businesses, universities, primary and secondary schools, and others that may not be well-trained in online safety will be especially vulnerable to this type of attack, especially if they are using a relatively new tool, like Piktochart.
I had not used Piktochart before, but this week, security researcher @pageinsec shared with me an infographic that asks the user to click on a link, in order to read a shared pdf document .
Piktochart has about 2,000 registered users, and about 24 million Piktocharts Created and is used by companies such as Forbes, TechCrunch, and others, according to their website. With a legitimate business purpose that is endorsed by some large companies, it is likely this is an effective way for the attackers to evade DNS filtering or other simple defenses against credential-stealing attacks.
Piktochart has a feature that makes it even better for phishing: Their registered "Pro users" can download an actual .pdf file, with the malicious link intact, or as well render the file into several different sizes of .png images, as indicated in the IOCs near the bottom of this page, which might be useful to hunt for similar activity.
An unsuspecting victim would receive an e-mail or social media post including the malicious Piktochart, from someone they knew, whose account had already been compromised. If they click the link, a 2nd stage credential stealer follows, which is a pretty decent-looking (but fake) Microsoft login page hosted at the domain obggladdenlightfoundation(.)org. This base domain currently has "0 out of 87" vendors reporting it as malicious on Virus Total, and is made out to be a non-profit in Lagos, Nigeria. This specific example had a different site registration than most of the other, identical sites I've researched, so it is possible this site was the result of a takeover of a legitimate business' WordPress website, or a redirection of the site's DNS.
Despite the technical simplicity, this is a dangerous campaign since it is after Microsoft 0365 credentials, and evidence points to the same IP being used for a large variety of credential theft sites. There are quite a few domains on the same IP, for example:
www.dhl-delivery-failure-resolve.naijamail.com - This one includes a nice-looking DHL form 
Indicators of compromise - IOCs
piktochart.com (if not needed for businses)
Domain registrar: 007NAMES INC.
*Used in most of the domains
Microssoft cred stealer image - hashes(sha2)
7, 10, and 3kb versions of the same image
DOM (cred-stealer page)
<form id="1MDAwMDMxMjAyMS0wMy0wMjE2MTQ2NTgwMDQ4NTgxMTAx"> <input type="hidden" value="[removed]"><input type="hidden" value="[removed"> </form>
"form id="f2" method="post" action="#" style="margin-bottom: 0px;"> <input required="" type="email" placeholder="Email, phone, or Skype" name="e"
style="outline:none; background-color:transparent;border:0px solid;height:30px;width:300px;font-weight:lighter;font-size:15px;margin-left:5px;padding-bottom:0px;padding-top:0px;"> <img
23:59:59 Name: PHPSESSID
23:59:59 Name: ip11
 - https://isc.sans.edu/forums/diary/The+new+LinkedInSecureMessage/27110
 - https://isc.sans.edu/forums/diary/Pretending+to+be+an+Outlook+Version+Update/27144/
 - https://apageinsec.wordpress.com/
 - https://create.piktochart.com/output/52653368-my-visual
 - https://urlscan.io/result/e02ea839-9671-4d31-a039-effd54877c0b/related/
 - https://urlscan.io/screenshots/205111b7-b981-48e9-9359-df55f278163b.png
 - https://isc.sans.edu/ipinfo.html?ip=126.96.36.199