Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Threat Intelligence

9/28/2018
08:00 AM
Kelly Sheridan
Kelly Sheridan
Slideshows
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

7 Most Prevalent Phishing Subject Lines

The most popular subject lines crafted to trick targets into opening malicious messages, gleaned from thousands of phishing emails.
Previous
1 of 8
Next

(Image: Amy Walters - stock.adobe.com)

(Image: Amy Walters stock.adobe.com)

Chances are good there's a phishing scam lurking amid your emails right now. If there isn't, then perhaps there will be tomorrow, or the next day. The question is, will you fall for it?

Phishing emails are getting tougher to block because attackers are crafting their bait to be more convincing to targets, researchers report. And employees are quick to open potentially malicious emails, even when they know they should be on alert, says Webroot CISO Gary Hayslip.

"I think it's to the point where it's getting commonplace," he says. "Users are used to seeing phishing emails now. They suck at not responding to them or clicking on them … which is frightening, because [attackers] prey on human nature."

People are curious and they want to help, he continues, and it's these two qualities that make them susceptible to phishing attacks. When they do fall for scams, most employees are quick to realize it. "I'm really busy," "I missed that," "I should've caught that email," are all commonly heard phrases from victims who have opened malicious emails and realized they did wrong.

"No matter how much technology you put in place to block them, stuff always gets through," Hayslip adds.

Webroot recently scanned thousands of phishing emails from the past 18 months to learn more about the trends around common subject lines designed to trick targets. Hayslip presented the findings to about 100 fellow CISOs around the country and learned "almost everybody's seeing the same thing," he says. Financially related messages and notions of urgency are commonly seen in phishing emails, albeit under different subject lines.

John "Lex" Robinson, cybersecurity strategist at Cofense (formerly PhishMe) echoes Hayslip's sentiments and says attackers are getting better and better at understanding the context of the emails they're sending and who they're targeting.

"If you think about the way we communicate today versus 15, 20, or 30 years ago, it's a lot less formal," he says. Phishing doesn't need to be formal; it needs to align with business jargon.

Here's a look at the most commonly used phishing subject lines, the messages they include, and what they reveal about their attackers' goals and tactics.

 

Black Hat Europe returns to London Dec 3-6 2018  with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions and service providers in the Business Hall. Click for information on the conference and to register.

 

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio

Previous
1 of 8
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
hixonmarie412
100%
0%
hixonmarie412,
User Rank: Author
10/17/2018 | 9:01:52 AM
Thank you for these!
Great read and I appreciate the article. I will definitely utilize these when testing our phisihing detection methods!
txreal
100%
0%
txreal,
User Rank: Apprentice
10/11/2018 | 12:31:40 PM
Please make slideshow available view in one page
Is there a way to have this feature (make slideshow available view in one page) to minimize down scroll? 

Thanks.

David
Joe Stanganelli
100%
0%
Joe Stanganelli,
User Rank: Ninja
9/29/2018 | 11:37:19 PM
Implied calls to action
The common thread in all of these and most others: they suggest a line of action to be taken beyond merely opening the email (handling a financial matter, picking up a package, addressing a bureaucratic snafu, etc.).

Another common one are emails that purport to be about HR issues.

And one that's picked up a lot of steam lately? The fake LinkedIn "[N] people searched for you".
I 'Hacked' My Accounts Using My Mobile Number: Here's What I Learned
Nicole Sette, Director in the Cyber Risk practice of Kroll, a division of Duff & Phelps,  11/19/2019
DevSecOps: The Answer to the Cloud Security Skills Gap
Lamont Orange, Chief Information Security Officer at Netskope,  11/15/2019
Attackers' Costs Increasing as Businesses Focus on Security
Robert Lemos, Contributing Writer,  11/15/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-13157
PUBLISHED: 2019-11-22
nsGreen.dll in Naver Vaccine 2.1.4 allows remote attackers to overwrite arbitary files via directory traversal sequences in a filename within nsz archive.
CVE-2012-2079
PUBLISHED: 2019-11-22
A cross-site request forgery (CSRF) vulnerability in the Activity module 6.x-1.x for Drupal.
CVE-2019-11325
PUBLISHED: 2019-11-21
An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. The VarExport component incorrectly escapes strings, allowing some specially crafted ones to escalate to execution of arbitrary PHP code. This is related to symfony/var-exporter.
CVE-2019-18887
PUBLISHED: 2019-11-21
An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. The UriSigner was subject to timing attacks. This is related to symfony/http-kernel.
CVE-2019-18888
PUBLISHED: 2019-11-21
An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. If an application passes unvalidated user input as the file for which MIME type validation should occur, then arbitrary arguments are passed to the underlying file command. T...