From EDU Account Takeover to Job Scam Abuse: West African Fraud Actors Target Universities

From EDU Account Takeover to Job Scam Abuse: West African Fraud Actors Target Universities
Proofpoint tracked a campaign targeting U.S. universities where attackers used compromised .edu accounts and fake password-verification forms to harvest credentials and PII. The same access was then used to push job-scam advance fee fraud involving fake checks, gift cards, and payment requests, with activity linked to Nigeria and tracking via Grabify. #Proofpoint #Grabify #Nigeria #UniversityEmailAccounts

Keypoints

  • Attackers targeted U.S. universities by abusing trusted university email accounts to reach students, staff, and alumni.
  • The initial phase used password verification or account-refresh lures that redirected victims to third-party forms.
  • Those forms harvested usernames, passwords, and PII such as names, phone numbers, and email addresses.
  • Threat actors did not rely on advanced AiTM or device code phishing; they used simpler form-based credential harvesting.
  • After account compromise, they sent job or internship offers that led victims into advance fee fraud schemes.
  • The fraud process escalated through fake checks, mobile deposits, gift card purchases, and requests for payment via Bitcoin, PayPal, and CashApp.
  • Proofpoint linked the activity to West African fraud operations, especially Nigeria, using tracking links and observed infrastructure.

MITRE Techniques

  • [T1566.002 ] Phishing: Spearphishing Link – Used to lure targets from email to a credential-harvesting form (‘the email directs the potential victim to fill out a web form on a third-party website’).
  • [T1056.002 ] Input Capture: GUI Input Capture – Victims entered credentials and PII into attacker-controlled web forms that collected the data (‘if the user fills out the form … that information is captured and sent to the threat actor’).
  • [T1583.001 ] Acquire Infrastructure: Domains – Threat actors hosted forms on legitimate third-party platforms to support the scam (‘hosted on legitimate services like Google forms, Wix, Jotform, Zoho Forms, and Microsoft Office’).
  • [T1585.001 ] Establish Accounts: Social Media Accounts – Not explicitly described; no clear account creation behavior was mentioned in the article.
  • [T1647 ] Acquire API Token – Not mentioned in the article; no API-token abuse was described.
  • [T1656 ] Impersonation – Actors pretended to be university staff or affiliates to make the scam believable (‘pretend to be university staff members, or an affiliate linked to the university’).
  • [T1589.002 ] Gather Victim Identity Information: Email Address – The forms collected university and personal email addresses as part of the fraud workflow (‘university email address, and personal email addresses’).
  • [T1087.004 ] Account Discovery: Cloud Account – The campaign relied on compromised university accounts and access to institutional email identities (‘By gaining access to a .edu account’).

Indicators of Compromise

  • [Domains / Platforms ] Hosting for fake credential and job forms – Google Forms, Wix, Jotform, Zoho Forms, Microsoft Office
  • [URL Shortening / Tracking Service ] Used to log clicks and reveal IP/device info – Grabify
  • [Geographic / Network Location ] Origin of observed fraudulent activity – Nigeria, West Africa
  • [Payment Services ] Requested for scam payments – PayPal, CashApp
  • [Cryptocurrency ] Alternative payment demand from scammers – Bitcoin
  • [Gift Card Payment Method ] Used after fraudulent check deposit – $100 gift cards, gift card codes
  • [Document / Check Artifact ] Fake payment instrument sent to victims – scanned copy of a check, about $1000
  • [Placeholder Text in Forms ] Password-replacement term used in phishing forms – WORDWORD


Read more: https://www.proofpoint.com/us/blog/threat-insight/edu-account-takeover-job-scam-abuse-west-african-fraud-actors-target