The Interplanetary File System (IPFS) is a decentralized file storage and access protocol designed to complement blockchain technology. Like the blockchain, the IPFS uses a decentralized network of nodes communicating over a peer-to-peer network to transfer information.
The IPFS enables users to upload, download, and share files via decentralized infrastructure. While this has its benefits, the IPFS can also be used in various cyberattacks.
The IPFS offers decentralized, low-cost hosting services. Anyone can upload files — including websites — to the IPFS, where they are accessed based on the file hash or via an IPFS gateway.
Using the IPFS, a cybercriminal can implement phishing infrastructure without hosting it themselves. Webpages hosted on the IPFS are static and have the ability to run JavaScript. Additionally, the design of the IPFS makes it very difficult to find these phishing pages, making them more difficult to take down.
A phishing site hosted on the IPFS is very similar to a phishing site hosted on traditional infrastructure, and the process for performing an IPFS phishing attack is similar to traditional phishing attacks. Some of the key steps in the process include:
After the attacker has collected enough sensitive data, they can take down the phishing page hosted on the IPFS. This makes it much more difficult for victims to track the source of the phishing attack.
Hosting phishing sites on the IPFS is just another way for a cybercriminal to build the infrastructure needed for a phishing campaign and evade detection. Many of the same best practices used for preventing traditional phishing attacks also apply to these IPFS phishing attacks, including:
The use of the IPFS to host phishing content is just another example of cybercriminals using new methods to make their phishing attacks more difficult to detect and prevent. The IPFS enables an attacker to inexpensively implement phishing infrastructure and can increase the difficulty of identifying and remediating these attacks.
Check Point’s ThreatCloud AI engine provides robust protection against IPFS phishing attacks. ThreatCloud AI identifies suspicious IPFS patterns and other indicators of phishing attacks and uses this information to block IPFS phishing content from reaching the intended recipient.
Check Point Harmony Email & Collaboration offers industry-leading protection against phishing attacks and is recognized as a Leader in the 2023 Forrester Wave for Enterprise Email Security. Learn how Harmony Email & Collaboration can protect your organization against IPFS phishing and other threats by signing up for a free demo today.