Description

Cybercriminals are utilizing Gamma AI, a website creation, presentation, and document-building platform, to create complex phishing redirectors that are hard to identify. Phishing websites are hosted on the legitimate domain of Gamma (gamma.app), with the links such as hxxps://gamma.app/docs/. On clicking these links, the victims are redirected through a series of intermediate pages, which incorporate CAPTCHA-like checks to simulate legitimate processes. Upon completing the CAPTCHA, clients are redirected either to a secured website or to an unsafe phishing site with a motive of gaining sensitive data. The abuse of Gamma AI is a result of its strong capabilities to enable its users to design professional sites and copy existing ones without programming knowledge. The attackers can easily duplicate legitimate websites, and their phishing campaigns will look credible. Moreover, Gamma's trusted domain and strong encryption model make it a suitable platform on which to host such redirectors, evading security scanners that tend to whitelist domains such as gamma.app, enabling the malicious links to pass undetected. To mitigate such threats, cyber security professionals advise increased domain surveillance, particularly for trusted sites such as Gamma AI to detect abuse. AI-based threat detection mechanisms can assist in detecting abnormal use patterns, while educating users about phishing methods with CAPTCHAs and proxy pages is important. Through an integration of technology and knowledge, security mechanisms can more effectively keep pace with sophisticated phishing threats and safeguard users against becoming victims of these advanced assaults.