{"id":33,"date":"2025-12-15T20:13:30","date_gmt":"2025-12-15T20:13:30","guid":{"rendered":"http:\/\/localhost\/?p=33"},"modified":"2025-12-15T20:13:30","modified_gmt":"2025-12-15T20:13:30","slug":"active-phishing-campaign","status":"publish","type":"post","link":"https:\/\/securityblog.denison.edu\/index.php\/2025\/12\/15\/active-phishing-campaign\/","title":{"rendered":"Active phishing campaign"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Denison&#8217;s cybersecurity intelligence is aware of multiple, ongoing phishing campaigns. These are very active campaigns, and they are attempting to steal account information in order to steal financial and student data.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We are attributing this campaign to a threat actor we track as <em>BLUECRAB<\/em>. Common themes in <em>BLUECRAB<\/em> attacks include account compromise originating from spear phishing leading to larger lateral phishing attacks. We believe that <em>BLUECRAB<\/em>&#8216;s attacks are financially motivated.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Who is this attack targeting?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>This attack is targeting students, faculty, and staff.<\/strong> Ensure that the contents of a message are safe before engaging with the message. If you don&#8217;t know the sender or the message looks suspicious, report it by forwarding the message to <a href=\"mailto:isitsafe@denison.edu\">isitsafe@denison.edu<\/a>. All messages are reviewed by a human during normal business hours.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What&#8217;s the danger?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">These campaigns contain a form (typically a Google Form) that requests personal information, including personal email addresses and\/or Denison account passwords. The contents of messages vary, but they originate from similar sources. Recent phishing message subject lines include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>IMPORTANT NOTICE: Extra cash flexible gigs<\/li>\n\n\n\n<li>General System Maintenance 12 \/ 15 \/ 2025\u2014 Act Fast!<\/li>\n\n\n\n<li>Flexible, Part-Time Personal Assistant \u2013 $30\/hour<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">As a reminder, <strong>NEVER send your password in an online form except for the Denison SSO page<\/strong>. You can verify the SSO page is real by looking in the address bar: the address should say identity[.]denison[.]edu. <strong>NEVER provide a multi-factor authentication (Duo) code that you didn\u2019t initiate through SSO<\/strong>, especially over SMS or text message.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you have any questions, notice strange behavior on your account (such as new email filters or messages you didn&#8217;t send), or suspect you may have provided information to the attackers, immediately contact the Service Desk.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Denison&#8217;s cybersecurity intelligence is aware of multiple, ongoing phishing campaigns. These are very active campaigns, and they are attempting to steal account information in order to steal financial and student data. We are attributing this campaign to a threat actor we track as BLUECRAB. Common themes in BLUECRAB attacks include account compromise originating from spear phishing leading to larger lateral phishing attacks. We believe that BLUECRAB&#8216;s attacks are financially motivated&#8230;.<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-33","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/securityblog.denison.edu\/index.php\/wp-json\/wp\/v2\/posts\/33","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/securityblog.denison.edu\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/securityblog.denison.edu\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/securityblog.denison.edu\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/securityblog.denison.edu\/index.php\/wp-json\/wp\/v2\/comments?post=33"}],"version-history":[{"count":0,"href":"https:\/\/securityblog.denison.edu\/index.php\/wp-json\/wp\/v2\/posts\/33\/revisions"}],"wp:attachment":[{"href":"https:\/\/securityblog.denison.edu\/index.php\/wp-json\/wp\/v2\/media?parent=33"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/securityblog.denison.edu\/index.php\/wp-json\/wp\/v2\/categories?post=33"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/securityblog.denison.edu\/index.php\/wp-json\/wp\/v2\/tags?post=33"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}