A new phishing campaign targets mostly California-based clients of Royal Bank of Canada. Its email comes with an HTML file attachment (detected as HTML_PHISH.TICOGEJ) with highly obfuscated Javascript in an attempt to make discovering its malicious URL more difficult. Like any other phishing campaign, this email is disguised to look like a legitimate request, but the email contains questionable elements such as the sender’s email address and the random file name of the attachment. The subject of the email also rings alarm bells with the random text at the end, although not all emails from this campaign share this characteristic. An example of the email can be seen below.

Clicking the HTML file opens the first layer redirect page on the user’s browser, landing eventually on the phishing site where threat actors behind this will be able to steal entered information. An image of the phishing page can be seen below.

We’ve detected more than 13,000 phishing emails related to this attack from July 22 and August 8, which is a sign that this is an ongoing campaign. Our detection data also indicates around three campaigns using this method may have been launched from the end of July to the present.

Campaigns like this show that while phishing is an old, well-known tactic, it's still a go-to method for cybercriminals. Reports from the past few months show how phishing continues to be used to target specific industries or spread malware. Users can avoid phishing attacks by being aware of its indicators and vigilant when online, especially when dealing with sensitive or financial information.

