<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Jotform - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/jotform/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 29 Sep 2026 10:23:29 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/jotform/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>West African Fraud Actors Targeting Universities via Compromised .edu Accounts</title><link>https://feed.craftedsignal.io/briefs/2026-09-west-african-edu-fraud/</link><pubDate>Tue, 29 Sep 2026 10:23:29 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-west-african-edu-fraud/</guid><description>West African threat actors are leveraging compromised university email accounts to distribute job-based advance fee fraud by harvesting credentials via legitimate third-party form services.</description><content:encoded><![CDATA[<p>Proofpoint researchers have identified a campaign by West African-based fraud actors targeting U.S. universities. The threat actors compromise .edu email accounts through credential harvesting lures, which they then use to distribute job-related advance fee fraud (AFF). The actors exploit the inherent trust associated with institutional email addresses to deceive students, staff, and alumni.</p>
<p>Rather than deploying custom phishing kits, the actors utilize legitimate form-building services, including Google Forms, Wix, Jotform, Zoho Forms, and Microsoft Office, to capture credentials and personally identifiable information (PII). By avoiding the use of explicit keywords like &quot;password&quot; in form fields, attackers attempt to bypass simple automated filters. Once an account is compromised, it is used to send legitimate-looking emails detailing fake job opportunities. Victims are subsequently coerced into mobile check deposits and the purchase of gift cards. The threat actors exhibit aggressive tactics, including threats of legal action and impersonation of law enforcement, if targets fail to comply with the financial demands.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker sends a phishing email to university targets claiming an account must be refreshed due to graduation or retirement.</li>
<li>The email redirects the victim to a legitimate third-party form provider (e.g., Google Forms, Jotform).</li>
<li>The victim provides account credentials and PII into the hosted form, bypassing filters by following attacker instructions (e.g., using &quot;WORDWORD&quot; as a placeholder for password).</li>
<li>The actor logs into the victim's university account using the harvested credentials.</li>
<li>The compromised account is used to send bulk emails impersonating faculty or staff, advertising fake remote job opportunities.</li>
<li>Victims interact with a second set of malicious forms that harvest personal and financial details.</li>
<li>The actor engages the victim via email or phone, instructing them to deposit a fraudulent check and purchase gift cards for &quot;employment&quot; costs.</li>
<li>If the victim resists, the actor escalates to threats, impersonation of law enforcement, or harassment to force payment.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>The campaign facilitates significant financial loss for university-affiliated victims through advance fee fraud. Compromised university accounts are used to maintain persistence and establish credibility for broader scam distribution. The aggregation of PII allows for secondary identity theft and more targeted future social engineering. While the number of victims is not explicitly stated, the broad nature of the campaign indicates a high-volume attempt to leverage institutional trust.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security teams to mitigate this threat:</p>
<ul>
<li>Enforce mandatory multi-factor authentication (MFA) across all university accounts to prevent account takeover via credential phishing.</li>
<li>Implement email filtering policies that flag or block emails containing links to common third-party form builders when sent from external sources or suspicious internal accounts.</li>
<li>Educate the user base on the indicators of job-based advance fee fraud, specifically the request for mobile check deposits followed by gift card purchases.</li>
<li>Monitor for anomalous login behavior or mass-emailing activity originating from internal .edu accounts, which may indicate an account compromise.</li>
<li>Investigate any reported &quot;IT&quot; communications that direct users to generic, third-party form-hosting websites rather than official university authentication portals.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>phishing</category><category>fraud</category><category>advance-fee-fraud</category><category>higher-education</category><category>social-engineering</category></item></channel></rss>