Fake Canva home page leads to browser lock


In a previous blog post, Malwarebytes researchers showed how fraudsters were leveraging features from the very company (Microsoft) they were impersonating.

Malwarebytes Labs continue this series with another clever trick abusing Canva, a popular online tool for graphic design. This time, the scammers registered an account on Canva to create a new design that, is in fact, a replica of the Canva home page. As victims come from a malicious ad, they land on this deceiving page that lures them into interacting with it. The result: as soon as you click on the image, your browser is hijacked with a fake Microsoft alert.

Read more…
Source: Malwarebytes Labs


Sign up for our Newsletter


Related:

  • Finastra Notifies Customers of Data Breach

    February 19, 2025

    British financial technology firm Finastra has notified customers impacted by a data breach that occurred over three months ago. Between October 31 and November 8, 2024, an unauthorized third party accessed the company’s secure file transfer platform (SFTP), used to share files with customers. Although the breach was detected on November 7, and the company acknowledged ...

  • Spam and phishing in 2024

    February 19, 2025

    In 2024, cybercriminals targeted travel enthusiasts using fake hotel and airline booking websites. In one simple scheme, a fraudulent site asked users to enter their login credentials to complete their booking — these credentials ended up in criminal hands. Sometimes, the fake login form appeared under multiple brand names at once (for example, both Booking ...

  • StaryDobry ruins New Year’s Eve, delivering miner instead of presents

    February 18, 2025

    On December 31, cybercriminals launched a mass infection campaign, aiming to exploit reduced vigilance and increased torrent traffic during the holiday season. Kaspersky telemetry detected the attack, which lasted for a month and affected individuals and businesses by distributing the XMRig cryptominer. This previously unidentified actor is targeting users worldwide—including in Russia, Brazil, Germany, Belarus and ...

  • UK: Man jailed for abusive emails to politicians

    February 18, 2025

    A 39-year-old man has been jailed for sending malicious communications to a government minister, the mayor of London and a senior Met Police officer. Jack Bennett, of Newlands Park, Seaton, Devon, pleaded guilty to four counts of sending malicious emails; one to Safeguarding Minister Jess Phillips, one to Metropolitan police officer Matt Twist, and two counts ...

  • Argentine judge investigates fraud case against President Milei over crypto promotion

    February 18, 2025

    A judge in Argentina was selected Monday to investigate allegations of fraud against President Javier Milei for his brief promotion of a cryptocurrency whose value collapsed within hours of its launch last week. Milei distanced himself from the scandal and said he acted in good faith. Milei and his office denied involvement with creators of the ...

  • 50,000 electronic attacks countered daily by UAE Cybersecurity Council

    February 17, 2025

    Dr. Mohammed Hamad Al Kuwaiti, Chairman of the UAE Cybersecurity Council, stated that the UAE possesses an advanced cybersecurity system capable of predicting and countering most electronic attacks before they occur. He noted that the average daily cyberattacks on key sectors exceeds 50,000, all of which are proactively deterred and mitigated. In statements to the Emirates ...