Print this Page

Microsoft 365 Users Targeted with Fake Voicemails

3/9/2022

In a new scam, cybercriminals attack Microsoft 365 users with malicious files disguised as voicemails. The scam works by sending an email with a voicemail file attached. The filename ends in “mth.mp3”, appearing to be a legitimate MP3 file. However, the file is actually a malicious HTML file that has been disguised using right-to-left override (RLO) functionality.

RLO was created 20 years ago for languages that read from left-to-right instead of right-to-left. Unfortunately, cybercriminals now use this functionality to make malicious files look safe. For example, in this scam, cybercriminals use RLO to display “mp3.htm” as “mth.mp3”. If you open the file, you will be taken to a fake Microsoft 365 login page instead of a voicemail. Then, any credentials that you enter on the fake login page will go straight to the cybercriminals.

Follow these tips to stay safe from similar scams:

• Never click links or download attachments in an email that you were not expecting.

• Before you share any sensitive information online, make sure that the website is legitimate. For example, an MP3 file should never take you to a login page. If you’re uncertain, navigate to the website directly.

• Before you share any sensitive information online, make sure that the website is legitimate. If you’re uncertain, navigate to the website directly before sharing any information.

• Remember that cybercriminals can use more than just links within emails to phish for your information. Always think before you click!

The KnowBe4 Security Team

KnowBe4.com

Fraud and Scams



« Return to "Money Talk Blog"
Comments
GregoryNeoma Gregorydek
9/7/2024 8:56 AM RonaldTuh R. from Toledo, SD
https://khelraja-india.com/download-app/
Gregoryhyday GregoryPoize
9/6/2024 1:19 AM CarsonRox C. from Bijeljina, OK
<a href="https://1xbetin.com/">Site 1xBet India</a>
GregoryLidly GregoryDiora
8/24/2024 5:55 PM ThomasVof T. from Keflavik, AZ
<a href="https://dosuchki1.ru">????? ??????????? ? ????????</a>
GregoryLam Gregorytraut
8/22/2024 7:47 PM Bennyzoosy B. from Kalamaria, TN
<a href="https://siski-138.ru/">???????? ???????</a>
Gregorytag Gregorydum
8/21/2024 3:51 PM RobertExicy R. from Kulim, SC
<a href="https://blyadsk.ru/na_vyezd">??????? ?? ????? ???????</a>
Gregoryannog Gregoryzet
8/16/2024 9:49 PM KevinRot K. from Kaduna, GA
<a href="https://s1.sosamba-spb2.ru/">??????????? ???????????? ???</a>
GregoryToB GregoryReuts
8/14/2024 6:32 PM Williambig W. from Montevideo, IA
<a href="https://sosamba-novg1.ru/leninskij-individualki">??????????? ?????? ???????? ????????? ?????</a>
Post Comment

(Only last initial will display on comment)

(Not displayed on Comment)




Security Code:
What's this?
Go to main navigation