A phishing site was found using a spoofed Netflix page to harvest account information, credit card credentials, and other personally identifiable information (PII), according to a twitter post by PartnerRe Information Security Analyst Andrea Palmieri. We looked into the malicious site, hxxp://secure-up-log.com/netflix/, to learn more about the operation and found that the sites have geolocation features.
Over the past few, we have seen other phishing campaigns that similarly use Netflix as bait; some threats even reference the Covid-19 outbreak at the same time. As people are spending time in quarantine due to coronavirus pandemic, video streaming platforms such as Netflix have become one of the most popular means to pass the time. Cybercriminals are taking advantage of this by using these apps to deceive unwitting users for phishing and other social engineering schemes.
Phishing sites seek to harvest sensitive information from victims. As they copy the user interface and spoof the website names, these malicious pages can be tricky to tell apart from legitimate log in sites. Below are some ways to avoid these threats:
I'm developing a website, in which I need to ensure that some pages won't be opened in more than one tab / browser. I need some sort of client identification. As I know MAC address cannot be queried using javascript.
I know that Netflix does something just like this, when opening two tabs of video watching, Netflix prompt an error that I'm already watching. Even if I'm using a different browser, Netflix can still tell I have another browser which is watching a video, which means they don't use cookies for this.
90f70e40cf