Endpoint

11/30/2018
04:00 PM
Kelly Sheridan
Kelly Sheridan
Slideshows
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail

Holiday Hacks: 6 Cyberthreats to Watch Right Now

'Tis the season for holiday crafted phishes, scams, and a range of cyberattacks. Experts list the hottest holiday hacks for 2018.
2 of 7

Festive Phishing Campaigns
Carbon Black's TAU found most attempted seasonal cyberattacks are the result of commodity malware delivered via spear-phishing campaigns. Attacks in recent years have targeted major brands, often via supply chain partners, resulting in losses of millions of customer records and credit card numbers - not to mention the financial cost of a breach for the affected businesses.
Inboxes are more crowded than usual during this time of year with the rise in online shopping, greetings, and travel plans. Attackers are using the influx of messages to trick people with fraudulent emails poisoned with bad links or attachments. Most of these arrive with subject lines that reference online shopping, event invitations, and order shipments, Cofense explains.
A common tactic is sending emails that link to an e-gift card, says Cofense co-founder and CTO Aaron Higbee. When clicked, it'll download a Word doc weaponized with an Office macro. When executed, that will drop and execute a sample of the Geodo/Emotet banking Trojan. 
'There are no new streams of malware we've identified in the past couple of months - just enhancements to existing delivery mechanisms,' he says. Some phishing emails are crafted to look like package deliveries and tracking notices.
'We're all in a kind of mindset of, 'Look out for things I could have potentially ordered,'' Higbee adds. If a fraudulent tracking notice slips into our inbox, we're unlikely to know it's fake, and fake tracking notices often aim to deliver malware.
(Image: Cofense)

Festive Phishing Campaigns

Carbon Black's TAU found most attempted seasonal cyberattacks are the result of commodity malware delivered via spear-phishing campaigns. Attacks in recent years have targeted major brands, often via supply chain partners, resulting in losses of millions of customer records and credit card numbers not to mention the financial cost of a breach for the affected businesses.

Inboxes are more crowded than usual during this time of year with the rise in online shopping, greetings, and travel plans. Attackers are using the influx of messages to trick people with fraudulent emails poisoned with bad links or attachments. Most of these arrive with subject lines that reference online shopping, event invitations, and order shipments, Cofense explains.

A common tactic is sending emails that link to an e-gift card, says Cofense co-founder and CTO Aaron Higbee. When clicked, it'll download a Word doc weaponized with an Office macro. When executed, that will drop and execute a sample of the Geodo/Emotet banking Trojan.

"There are no new streams of malware we've identified in the past couple of months just enhancements to existing delivery mechanisms," he says. Some phishing emails are crafted to look like package deliveries and tracking notices.

"We're all in a kind of mindset of, 'Look out for things I could have potentially ordered,'" Higbee adds. If a fraudulent tracking notice slips into our inbox, we're unlikely to know it's fake, and fake tracking notices often aim to deliver malware.

(Image: Cofense)

2 of 7
Comment  | 
Print  | 
Comments
Newest First  |  Oldest First  |  Threaded View
'PowerSnitch' Hacks Androids via Power Banks
Kelly Jackson Higgins, Executive Editor at Dark Reading,  12/8/2018
The Case for a Human Security Officer
Ira Winkler, CISSP, President, Secure Mentem,  12/5/2018
Windows 10 Security Questions Prove Easy for Attackers to Exploit
Kelly Sheridan, Staff Editor, Dark Reading,  12/5/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
10 Best Practices That Could Reshape Your IT Security Department
This Dark Reading Tech Digest, explores ten best practices that could reshape IT security departments.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-8651
PUBLISHED: 2018-12-12
A cross site scripting vulnerability exists when Microsoft Dynamics NAV does not properly sanitize a specially crafted web request to an affected Dynamics NAV server, aka "Microsoft Dynamics NAV Cross Site Scripting Vulnerability." This affects Microsoft Dynamics NAV.
CVE-2018-8652
PUBLISHED: 2018-12-12
A Cross-site Scripting (XSS) vulnerability exists when Windows Azure Pack does not properly sanitize user-provided input, aka "Windows Azure Pack Cross Site Scripting Vulnerability." This affects Windows Azure Pack Rollup 13.1.
CVE-2018-8617
PUBLISHED: 2018-12-12
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8583, CVE-2018-8...
CVE-2018-8618
PUBLISHED: 2018-12-12
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8583, CVE-2018-8...
CVE-2018-8619
PUBLISHED: 2018-12-12
A remote code execution vulnerability exists when the Internet Explorer VBScript execution policy does not properly restrict VBScript under specific conditions, aka "Internet Explorer Remote Code Execution Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Exp...