West African Fraud Actors Target Universities With Account Takeovers and Job Scams

Summary
Proofpoint describes a campaign that harvests university credentials and personal information through online forms, then uses compromised accounts to promote fraudulent jobs and advance-fee scams.
Key points
- Lures ask university students, staff, and alumni to verify or refresh accounts through forms hosted on services such as Google Forms, Wix, and Microsoft Office.
- The forms collect credentials and personal information; attackers may disguise password fields with placeholders such as “WORDWORD.”
- Compromised university accounts send job and internship lures that lead to more forms collecting applicants’ personal and financial details.
- In the observed advance-fee scam, victims are sent a fraudulent check, told to deposit it, keep part of the money, and buy gift cards with the rest.
- Proofpoint says the actors did not use adversary-in-the-middle or device-code phishing; account takeover requires that the account lack multifactor authentication.
- Researchers traced the activity in their engagements to operations in Nigeria and recommend MFA and caution around unsolicited job offers or requests for money.
Article Details
- Attack Vectors
- Emails warning of university account deactivation or requesting password verification direct recipients to third-party forms that collect credentials and personal information. Some forms use the placeholder “WORDWORD” for a password field.
- After compromising university email accounts, the actors send job and internship offers that link to fraudulent application forms collecting personal, banking, or payment information.
- In the reported job scams, actors send a fraudulent check, instruct the target to deposit it, and ask for gift card codes purchased with part of the apparent proceeds. They also suggested Bitcoin or payment services when targets did not comply.
- Defensive Notes
- Require multifactor authentication on all accounts; Proofpoint says the reported account takeovers depend on accounts lacking a second factor.
- Treat unsolicited job offers cautiously, including those received through institutional email, social media, or SMS.
- Do not send money to someone claiming to be an employer, including by purchasing gift cards after depositing a check.
MITRE ATT&CK
T1078 · Valid AccountsThe actors use valid credentials obtained through phishing to access university email accounts and send fraudulent job offers.T1566.002 · Spearphishing LinkCredential-phishing emails link university recipients to forms that collect account credentials and personal information.T1586.002 · Email AccountsThe actors compromise university email accounts after harvesting credentials, then use those accounts to distribute job-scam emails.
Products
Google formsThen, the recipient is directed to a web-based form, hosted on legitimate services like Google forms, Wix, Jotform, Zoho Forms, and Microsoft Office.JotformThen, the recipient is directed to a web-based form, hosted on legitimate services like Google forms, Wix, Jotform, Zoho Forms, and Microsoft Office.Microsoft OfficeThen, the recipient is directed to a web-based form, hosted on legitimate services like Google forms, Wix, Jotform, Zoho Forms, and Microsoft Office.WixThen, the recipient is directed to a web-based form, hosted on legitimate services like Google forms, Wix, Jotform, Zoho Forms, and Microsoft Office.Zoho FormsThen, the recipient is directed to a web-based form, hosted on legitimate services like Google forms, Wix, Jotform, Zoho Forms, and Microsoft Office.