Proofpoint tracked a campaign targeting U.S. universities where attackers used compromised .edu accounts and fake password-verification forms to harvest credentials and PII. The same access was then used to push job-scam advance fee fraud involving fake checks, gift cards, and payment requests, with activity linked to Nigeria and tracking via Grabify. #Proofpoint #Grabify #Nigeria #UniversityEmailAccounts
Keypoints
- Attackers targeted U.S. universities by abusing trusted university email accounts to reach students, staff, and alumni.
- The initial phase used password verification or account-refresh lures that redirected victims to third-party forms.
- Those forms harvested usernames, passwords, and PII such as names, phone numbers, and email addresses.
- Threat actors did not rely on advanced AiTM or device code phishing; they used simpler form-based credential harvesting.
- After account compromise, they sent job or internship offers that led victims into advance fee fraud schemes.
- The fraud process escalated through fake checks, mobile deposits, gift card purchases, and requests for payment via Bitcoin, PayPal, and CashApp.
- Proofpoint linked the activity to West African fraud operations, especially Nigeria, using tracking links and observed infrastructure.
MITRE Techniques
- [T1566.002 ] Phishing: Spearphishing Link – Used to lure targets from email to a credential-harvesting form (‘the email directs the potential victim to fill out a web form on a third-party website’).
- [T1056.002 ] Input Capture: GUI Input Capture – Victims entered credentials and PII into attacker-controlled web forms that collected the data (‘if the user fills out the form … that information is captured and sent to the threat actor’).
- [T1583.001 ] Acquire Infrastructure: Domains – Threat actors hosted forms on legitimate third-party platforms to support the scam (‘hosted on legitimate services like Google forms, Wix, Jotform, Zoho Forms, and Microsoft Office’).
- [T1585.001 ] Establish Accounts: Social Media Accounts – Not explicitly described; no clear account creation behavior was mentioned in the article.
- [T1647 ] Acquire API Token – Not mentioned in the article; no API-token abuse was described.
- [T1656 ] Impersonation – Actors pretended to be university staff or affiliates to make the scam believable (‘pretend to be university staff members, or an affiliate linked to the university’).
- [T1589.002 ] Gather Victim Identity Information: Email Address – The forms collected university and personal email addresses as part of the fraud workflow (‘university email address, and personal email addresses’).
- [T1087.004 ] Account Discovery: Cloud Account – The campaign relied on compromised university accounts and access to institutional email identities (‘By gaining access to a .edu account’).
Indicators of Compromise
- [Domains / Platforms ] Hosting for fake credential and job forms – Google Forms, Wix, Jotform, Zoho Forms, Microsoft Office
- [URL Shortening / Tracking Service ] Used to log clicks and reveal IP/device info – Grabify
- [Geographic / Network Location ] Origin of observed fraudulent activity – Nigeria, West Africa
- [Payment Services ] Requested for scam payments – PayPal, CashApp
- [Cryptocurrency ] Alternative payment demand from scammers – Bitcoin
- [Gift Card Payment Method ] Used after fraudulent check deposit – $100 gift cards, gift card codes
- [Document / Check Artifact ] Fake payment instrument sent to victims – scanned copy of a check, about $1000
- [Placeholder Text in Forms ] Password-replacement term used in phishing forms – WORDWORD