Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Cloud

6/11/2018
12:30 PM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

Fewer Phishing Attacks Hit More Diverse Targets

Nearly 300 brands were hit with phishing attacks in Q1, with cloud storage providers now among the top 10 most targeted.

Phishing detections are down for the second consecutive quarter, RiskIQ researchers report, but attacks are hitting a more diverse set of brands. A total of 299 unique brands were targeted with phishing attacks in Q1 2018, up from 259 brands in Q4 2017.

It's worth noting the decline is slight, at 2%, report RiskIQ researchers in their Q1 2018 Phishing Roundup and 2017 Recap. Data on targeted brands was richer than it has been in the past, with cloud storage providers now appearing in the top 10 most targeted for Q1.

The arrival of cloud storage providers shows attackers are phishing a more diverse pool of brands. At 40% of targets, financial institutions remain the most frequently hit, followed by digital transaction providers (20%), large tech companies (10%), major health insurance providers (10%), cloud storage providers (10%), and social media platforms (10%).

It's not unusual to see financial companies commonly targeted, researchers point out, but attackers are using different means to phish them. Much of social media as a target from Q4 2017 is "now mostly gone," a sign of threat actors turning back to older tactics, according to the researchers.

GoDaddy led the list of registrars used by phishing URLs in Q1, followed by Register.com, PublicDomainRegistry.com, eNom, and Tocows Domains. This marks a major shift from the previous quarter, when Hostinger led the pack. Now it has dropped from the top five registrars entirely, which researchers attribute to the cyclical nature of phishing attacks and their infrastructure.

Names also shifted in the top hosting providers used by phishing attackers in Q1, with all top five moving positions and three new names on the list. The top hosting provider for phishing URLs was Unified Layer, followed by CyrusOne, Bizineshost-AS, OVH, and Global Net Access.

"Phishing actors are constantly changing infrastructure, so they have shopped elsewhere in Q1 rather than using the same tools from Q4," RiskIQ reports.

Related Content:

 

Top industry experts will offer a range of information and insight on who the bad guys are – and why they might be targeting your enterprise. Click for more information

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
US Turning Up the Heat on North Korea's Cyber Threat Operations
Jai Vijayan, Contributing Writer,  9/16/2019
MITRE Releases 2019 List of Top 25 Software Weaknesses
Kelly Sheridan, Staff Editor, Dark Reading,  9/17/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: "He's too shy to invite me out face to face!"
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-9405
PUBLISHED: 2019-09-20
The wp-piwik plugin before 1.0.5 for WordPress has XSS.
CVE-2015-9407
PUBLISHED: 2019-09-20
The xpinner-lite plugin through 2.2 for WordPress has xpinner-lite.php XSS.
CVE-2015-9408
PUBLISHED: 2019-09-20
The xpinner-lite plugin through 2.2 for WordPress has wp-admin/options-general.php CSRF with resultant XSS.
CVE-2019-16533
PUBLISHED: 2019-09-20
On DrayTek Vigor2925 devices with firmware 3.8.4.3, Incorrect Access Control exists in loginset.htm, and can be used to trigger XSS. NOTE: this is an end-of-life product.
CVE-2019-16534
PUBLISHED: 2019-09-20
On DrayTek Vigor2925 devices with firmware 3.8.4.3, XSS exists via a crafted WAN name on the General Setup screen. NOTE: this is an end-of-life product.