Home OSINT News Signals
CYBER

How scammers use legitimate surveys to link to malicious sites | Kaspersky official blog

🕓 1 min read

EXCLUSIVE: SURVEY SCAM EPIDEMIC EXPLOITS TRUSTED PLATFORMS IN MASSIVE PHISHING OFFENSIVE

A chilling new wave of cyberattacks is turning everyday feedback forms into weapons. Security analysts are sounding the alarm as criminals weaponize legitimate survey tools from platforms like Yandex and Google to launch devastating phishing campaigns, bypassing enterprise defenses with terrifying ease. This isn't just spam; it's a calculated data breach operation hiding in plain sight.

The scheme is deceptively simple yet brutally effective. Attackers create surveys on reputable services, embedding malicious links to fake crypto exchanges or malware-dropping sites directly within the poll. These links are cloaked by the trusted domain, allowing them to sail past standard email filters. Recipients see a URL ending in yandex.com or forms.gle and let their guard down, clicking straight into the trap. This exploit of inherent platform trust represents a new frontier in social engineering.

Internal telemetry from a leading cybersecurity firm reveals an explosive, near 15-fold monthly increase in blocked attacks using this method, skyrocketing from 2,200 incidents to over 32,000 in just thirty days. This vertical spike signals an aggressive, coordinated shift in criminal tactics focused on quality over quantity, targeting individuals and corporations alike.

"These are not amateur operations," revealed a senior threat intelligence analyst, speaking on condition of anonymity. "We are observing highly organized groups leveraging these surveys as the initial access point for ransomware deployments and credential harvesting. They are exploiting a fundamental vulnerability in how we perceive trust online. The zero-day here is in human psychology, not software."

Every employee who clicks a "harmless" survey link is a potential gateway for a catastrophic network intrusion. This method directly threatens corporate crypto assets and challenges the very principles of blockchain security by targeting the individual keys held in company wallets. Your organizational hygiene is now the primary attack surface.

This trend will not plateau. Expect a flood of copycat campaigns exploiting every major platform with a survey function, leading to the next major corporate breach headline. The arms race between spam filters and these weaponized legitimate tools has just entered a dangerous new phase.

When your next feedback request arrives, remember: trust no link, verify every sender. The survey you take could be surveying you for attack.

Telegram X LinkedIn
Back to News