Endpoint

2/25/2016
05:00 PM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Phishing Attacks Increase Tech Sophistication, Focus On Financial Fraud

With a prevalence of free, feature-rich phishing kits and multi-million dollar profits from business email compromise attacks, no wonder phishing's so popular.

Phishing attacks are becoming more sophisticated, even when the attackers themselves aren't. Basic, even free, phishing kits now contain a variety of clever functions, as well as obfuscation and anti-analysis techniques, according to a report released today by PhishLabs.

Phishing kits now often include features like pre-filled form data, high-quality emulation, live polls, and chained forms with false error messages to encourage victims to share more information, and phishing pages for mobile platforms. They're equipped with measures that allow them to impersonate legitimate businesses without being flagged by Web crawlers and identified as phishing pages.

More sophisticated attackers may sell phishing kits to amateurs on the black market for anywhere from $1 to $50 to turn a profit. According to PhishLabs, some others are making their kits freely available -- with a backdoor secretly installed in the code so those thrifty amateur phishers unknowingly export all the data they steal straight back to the malware writer, who can then sell that for a profit.

According to the report, spearphishing remains APT groups' intial attack vector of choice. It's financial fraud and similar crimes, however that were the focus of the most spearphishing attacks, accounting for 22 percent. 

Among them were business email compromise (BEC) attacks, which increased in 2015. BEC attacks begin with extensive reconaissance about the personnel within an organization. By posing as executives within the company (or company partners), phishers convince employees with spending authority to send wire transfers to attacker-controlled accounts -- sometimes taking individual companies for tens of millions of dollars.

According to the PhishLabs report, BEC fraudsters have begun to increase their use of ploys that reference mergers and acquisitions, as opposed to less sensitive operations, to "reinforce the need for secrecy." Ploys that purport to quote conversations with lawyers are particularly successful at convincing the same victim to make multiple payments.

Further, the researchers found that BEC attackers' biggest costs are managing the money mule accounts they use to receive payments and withdraw cash. It's the campaigns' largest investments, often costing more than all other overhead combined.

Other interesting findings: the top industries that were targeted by consumer phishing (not spearphishing) were finance, cloud hosting, online services, e-commerce, and payment services. The researchers also found that Gmail was attackers' drop location of choice for receiving stolen credentials, making up 57% of drop email accounts.


Related stories:

Interop 2016 Las VegasFind out more about security threats at Interop 2016, May 2-6, at the Mandalay Bay Convention Center, Las Vegas. Register today and receive an early bird discount of $200.

Sara Peters is Senior Editor at Dark Reading and formerly the editor-in-chief of Enterprise Efficiency. Prior that she was senior editor for the Computer Security Institute, writing and speaking about virtualization, identity management, cybersecurity law, and a myriad ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
6 Ways Greed Has a Negative Effect on Cybersecurity
Joshua Goldfarb, Co-founder & Chief Product Officer, IDRRA ,  6/11/2018
Weaponizing IPv6 to Bypass IPv4 Security
John Anderson, Principal Security Consultant, Trustwave Spiderlabs,  6/12/2018
'Shift Left' & the Connected Car
Rohit Sethi, COO of Security Compass,  6/12/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-12026
PUBLISHED: 2018-06-17
During the spawning of a malicious Passenger-managed application, SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows such applications to replace key files or directories in the spawning communication directory with symlinks. This then could result in arbitrary reads and writes, which in tur...
CVE-2018-12027
PUBLISHED: 2018-06-17
An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 causes information disclosure in the following situation: given a Passenger-spawned application process that reports that it listens on a certain Unix domain socket, if any of the parent directories of said ...
CVE-2018-12028
PUBLISHED: 2018-06-17
An Incorrect Access Control vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows a Passenger-managed malicious application, upon spawning a child process, to report an arbitrary different PID back to Passenger's process manager. If the malicious application then generates an e...
CVE-2018-12029
PUBLISHED: 2018-06-17
A race condition in the nginx module in Phusion Passenger 3.x through 5.x before 5.3.2 allows local escalation of privileges when a non-standard passenger_instance_registry_dir with insufficiently strict permissions is configured. Replacing a file with a symlink after the file was created, but befor...
CVE-2018-12071
PUBLISHED: 2018-06-17
A Session Fixation issue exists in CodeIgniter before 3.1.9 because session.use_strict_mode in the Session Library was mishandled.