Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

ABTV //

Phishing

End of Bibblio RCM includes -->
6/25/2018
11:05 AM
Scott Ferguson
Scott Ferguson
News Analysis-Security Now

Phishing Attacks Are Increasing & Gaining in Sophistication

Reports from Palo Alto Networks and Barracuda Networks show that different types of phishing attacks are increasing, and becoming more sophisticated and deceptive.

Phishing attacks remain one of the oldest types of security concerns for enterprises, but that doesn't mean they have lost their ability to trick end-users into clicking. In fact, recent reports show increasingly sophisticated and deceptive schemes.

The number of phishing attacks has been on an uptick in the last two months, according to one report, released Monday, from Barracuda Networks. The company's software blocked more than 1.5 million phishing emails in May, and research observed over 10,000 unique attempts.

In June so far, Barracuda blocked 1.7 million phishing emails with more than 2,000 unique attempts.

Phishing email disguised as message from a bank\r\n(Source: Barracuda Networks)\r\n
Phishing email disguised as message from a bank
\r\n(Source: Barracuda Networks)\r\n

Jonathan Tanner, a software engineer with Barracuda and the author of the June 25 study, wrote in an email to Security Now that it's difficult to determine why phishing emails increase or decrease in certain months.

"Generally speaking, there's always a chance that criminals could take advantage of current events, holidays, etc. to base campaigns around," Tanner wrote. "This could be anything from composing messages around summer sales, for example, or right now we have the World Cup going on -- it wouldn't be surprising to see a phishing campaign based on either of those subjects."

In fact, Check Point noted a specific phishing scam targeting World Cup fans that started around the time the tournament began in early June. (See World Cup Penalty: Phishing Campaign Targets Soccer Fans.)

The Barracuda report follows similar analysis from Palo Alto Networks' Unit 42, which published a blog post on June 18, that looked at phishing emails for the first quarter of this year. Overall, researchers noted that while exploit kits had declined, the number of malicious emails had not.

Specifically, Palo Alto found over 150 phishing domains being hosted in the US, with the next closest being Germany with 28. Poland had 13.

"In the first quarter of 2018, we found 4,213 URLs from 262 unique domains used in phishing attacks. On average, we found one domain serving 16 different phishing URLs," according to the blog post.


Boost your understanding of new cybersecurity approaches at Light Reading's Automating Seamless Security in Carrier & Enterprise Networks event on October 17 in Chicago! Service providers and enterprises receive FREE passes. All others can save 20% off passes using the code LR20 today!

In his email, Tanner noted that the rise of malware-as-a-service makes these types of attacks much easier to start, as well as more profitable for the people behind them.

"Credentials, whether phished directly or obtained through malware, are a profitable commodity at scale so there is certainly an incentive to break into this market," Tanner wrote. "As another example of copying the SaaS model, botnets are 'rented' for distribution of such emails, making logistics easier. Ransomware has been a big contributor over the past few years as well, although it's likely to decrease as protections are put in place on the victim-side, prevalence of victims not receiving their files post-ransom payment increases, and fewer victims opt to pay the ransom."

And this is where an increasingly level of sophistication comes in.

Along with new statistics, Barracuda released several examples of phishing emails, including one that distributes malware by urging the reader to open an attachment that relates to an urgent matter. From there, the attackers can distribute viruses, worms, bots, ransomware, password stealers and more.

In another example, Barracuda researchers found a spear phishing campaign involving cybercriminals registering domain names and involved in "typosquatting," specifically misspelling Netflix as "Netfliix" in order to get the email reader to click on a link or attachment.

"It's possible that less sophisticated attackers will increase their sophistication level as they familiarize themselves with the techniques available, but there will likely always be a large number of newcomers to the market as well that use unsophisticated techniques and poor grammar," Tanner noted. "Ultimately, if an attacker achieves their goals with a lower level of sophistication, there isn't much incentive to increase it. I think there will always be a place for both highly sophisticated attacks that are barely differentiable than real email as well as unsophisticated, mass attacks that simply rely on a few users falling for the trick."

Related posts:

— Scott Ferguson is the managing editor of Light Reading and the editor of Security Now. Follow him on Twitter @sferguson_LR.

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Improving Enterprise Cybersecurity With XDR
Enterprises are looking at eXtended Detection and Response technologies to improve their abilities to detect, and respond to, threats. While endpoint detection and response is not new to enterprise security, organizations have to improve network visibility, expand data collection and expand threat hunting capabilites if they want their XDR deployments to succeed. This issue of Tech Insights also includes: a market overview for XDR from Omdia, questions to ask before deploying XDR, and an XDR primer.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-27509
PUBLISHED: 2022-06-26
Persistent XSS in Galaxkey Secure Mail Client in Galaxkey up to 5.6.11.5 allows an attacker to perform an account takeover by intercepting the HTTP Post request when sending an email and injecting a specially crafted XSS payload in the 'subject' field. The payload executes when the recipient logs in...
CVE-2022-34491
PUBLISHED: 2022-06-25
In the RSS extension for MediaWiki through 1.38.1, when the $wgRSSAllowLinkTag config variable was set to true, and a new RSS feed was created with certain XSS payloads within its description tags and added to the $wgRSSUrlWhitelist config variable, stored XSS could occur via MediaWiki's template sy...
CVE-2022-29931
PUBLISHED: 2022-06-25
Raytion 7.2.0 allows reflected Cross-site Scripting (XSS).
CVE-2022-31017
PUBLISHED: 2022-06-25
Zulip is an open-source team collaboration tool. Versions 2.1.0 through and including 5.2 are vulnerable to a logic error. A stream configured as private with protected history, where new subscribers should not be allowed to see messages sent before they were subscribed, when edited causes the serve...
CVE-2022-31016
PUBLISHED: 2022-06-25
Argo CD is a declarative continuous deployment for Kubernetes. Argo CD versions v0.7.0 and later are vulnerable to an uncontrolled memory consumption bug, allowing an authorized malicious user to crash the repo-server service, resulting in a Denial of Service. The attacker must be an authenticated A...