Skip to main content

Heatstroke Phishing Kit

First observed in early 2019, Heatstroke is an advanced phishing kit that uses sophisticated techniques to avoid detection and increase the likelihood of obtaining sensitive user information.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

First observed in early 2019, Heatstroke is an advanced phishing kit that uses sophisticated techniques to avoid detection and increase the likelihood of obtaining sensitive user information.


Threat details

Heatstroke's operators conduct extensive reconnaissance on prospective targets, preferring to target free email services such as Gmail and Outlook Online. These services are of particular interest as they are typically less secure than paid mail services, and are commonly used as verification addresses for other services. Once suitable targets are identified, Heatstroke will employ the following process:

  1. A phishing email, containing a link to the phishing site, is sent to the targeted users from a legitimate domain. The appearance of these emails is very similar to those of the service Heatstroke is attempting to spoof, in some cases using the same HTML formatting.
  2. The user is then taken to a landing page. Heatstroke uses a multi-stage site to more accurately mimic the behaviour of a legitimate website. This first-stage is designed to bypass content filters, and is used to direct the user to the second-stage.
  3. The second-stage site will collect system and user information before performing a number of checks to verify the identity of the user. If any irregularities are detected, this stage will terminate the process and return a 403 HTTP error.
  4. If the user passes all second-stage checks, they are directed to a third-stage page containing dynamically generated phishing fields.
  5. Once the user completes these fields the information is encoded within an image and sent to an operator-owned email address. The phishing site then becomes unresponsive, and will be inaccessible once the user navigates away from it.

Remediation steps

Type Step

To prevent and detect an infection, ensure that:

  • A robust program of education and awareness training is delivered to users to ensure they don’t open attachments or follow links within unsolicited emails.
  • All operating systems, anti-virus and other security products are kept up-to-date.
  • Regular anti-virus and security scans are performed on your organisation’s estate.
  • All day-to-day computer activities such as email and internet are performed using non-administrative accounts.
  • Strong password policies are in place.
  • Network, proxy and firewall logs should be monitored for suspicious activity.
  • User accounts accessed from affected devices should be reset on a clean computer.
  • Your organisation adopts a holistic all-round approach to Cyber Security as advocated by the 10 Steps to Cyber Security.

Last edited: 14 February 2020 2:54 pm