Types of Phishing Attacks and How to Detect Them

Types of Phishing Attacks and How to Detect Them


Types and Tools of Phishing, the Problem of Targeted Attacks, Examples Of letters and Phishing Prevention

Virtually every data breach and all online attacks today involve some form of a phishing attempt to steal passwords, launch fraudulent transactions, or trick the recipient of a message into downloading malicious software. According to PhishMe, in early 2016, 93% of phishing emails were delivered using ransomware.

Security experts regularly remind users to watch out for phishing attacks, but many simply don't know how to recognize them as attacks can take many forms. “Phishing attacks come in many different forms, targeting specific individuals in an organization who have access to sensitive data” comments Shalab Mohan of Area 1 Security.

Users tend to be poor at recognizing the actions of fraudsters. According to Verizon's cybersecurity report, an attacker who sends 10 phishing emails has a 90 percent chance of one person being trapped. This seems absurd at first, but only when it comes to technology users, not manufacturing or education users. Add to that the fact that not all phishing emails work the same: some are regular emails and others are carefully designed to target a specific type of people, and it becomes increasingly difficult to teach users to be careful when the message seems a little strange.

Let's take a look at the different types of phishing attacks and how to recognize them.

What is Phishing

Phishing is the mass distribution of emails. The most common form of phishing is bulk email, where someone sends an email impersonating someone else and tries to trick the recipient into performing actions that usually involve logging in to a website or downloading malware. Attacks are often based on email spoofing, where the email header, the From field, is spoofed to make the message look as if it was sent to someone the recipient trusts.

What can happen if you still mistake a phishing email for a real one?

1.    After receiving a letter from a supposed acquaintance, you can follow a dangerous link or download a file containing a malicious program. It can cause significant damage.

2.    If the scammers convince you of the truth of their story, it is possible that you will want to transfer money to them. So you can lose even a large amount.

3.    You can send your financial data or work files to attackers. This will lead to the loss of your personal or company funds, and therefore to problems at work.

4.    Under the guise of your acquaintances, scammers can get into your confidence and use whatever they can find out from you for extortion.

What You Should Pay Attention to

Be wary if you see a call to enter any of your data - in the letter itself, by reference or in any other way. None of the services you use will ever ask for your data, they are already in the system. However, attackers may well send a letter like the one shown in

Another example of a phishing email is shown in Figure 2. Notice how the text is composed. It contains a direct indication that your profile will be blocked if you do not follow the instructions contained in the letter. This is manipulation and a clear sign that the letter was written by scammers.

Phishing email

However, phishing attacks don't always look like a UPS delivery notification email, or a warning message from PayPal about password expiration, or an Office 365 email about storage quotas. Some attacks target organizations and individuals specifically, while others use methods other than email.

Business email compromise

In addition to massive, widespread phishing campaigns, criminals target key individuals in the finance and accounting departments through email fraud, business email compromise (BEC), and CEO email manipulation. By posing as financial officials and CEOs, these criminals try to trick victims into transferring money to unauthorized accounts.

Typically, attackers compromise a manager's or CFO's email account using various methods. The fraudster secretly monitors the email activity of the manager for a certain period in order to find out about the processes taking place in the company. The actual attack takes the form of a fake email that looks like it came from a compromised manager's account and is sent to whoever is the regular recipient of such emails. The letter appears to be important and urgent and requires the recipient to send a bank transfer to an external or unfamiliar bank account. The money eventually ends up in the attacker's bank account.

According to the FBI's Internet Crime Complaints Center, fraudulent activities such as the BEC have resulted in actual losses of over $ 4.5 billion and are a global problem. An example of such a letter is shown in Figure 3. Notice that the letter indicates a high priority task. This may well be a manipulation thought out by an attacker. Regardless of the way the letter is worded, if it involves the implementation of actions that are dangerous to your company or reputation, it should be ignored.

. An example of a BEC attack

Remember that the following actions are considered dangerous:

·         sending data;

·         sending money;

·         following a link;

·         opening an attachment;

·         installing the application;

·         following the link to the site, followed by registration with an account (by entering a username and password).

The Problem of Targeted Attacks

Spear-phishing attacks are the process of sending emails to specific recipients on behalf of a supposedly safe sender. The goal is to infect devices with malware or convince the victim to transfer information or money. Phishing attacks began as a scam to obtain money from "Nigerian princes" in the mid-1990s. They have now evolved into effective, well-designed, and targeted campaigns.

Phishing targeted attacks get their name from the fact that scammers catch random victims using fake or fraudulent email as bait. Using targeted phishing attacks, attackers target victims, and high-value organizations. Instead of trying to get 1,000 consumers' bank credentials, it may be more profitable for a fraudster to target multiple businesses.

In a recent phishing campaign, Group 74 (also known as Soft, APT28, Fancy Bear) targeted cybersecurity professionals. An email was written purportedly related to the Cyber ​​Conflict US conference and events organized by the United States Military Academy Army Cyber ​​Institute, NATO Cooperative Cyber ​​Military Academy, and NATO Cooperative Cyber ​​Defense Center of Excellence. Although CyCon is a real conference, the attachment was a document containing a malicious Visual Basic for Applications (VBA) macro that downloaded and ran malware intelligence software called Seduploader.

What is the fundamental difference between phishing attacks and spear-phishing attacks? While conventional phishing campaigns have a large number of targets with relatively low performance, spear-phishing is a targeted attack using emails crafted specifically for the intended victim.

"Phishing is a typical low-tech attack," said Aaron Higby, co-founder, and CTO of anti-phishing firm Cofense, formerly known as PhishMe. - Attackers don't really care who their target is. They just use a large net trying to catch as many fish as possible. Spear phishing is a campaign that is purposefully built to penetrate one organization, preceded by a study of names and processes within the company. "

If mass phishing primarily involves the use of off-the-shelf automated kits for mass credential collection using fake login pages for regular banking or postal services or distributing ransomware or encryption malware, then targeted phishing attacks are more complex. Some targeted campaigns use documents containing malware or website links to steal credentials in order to obtain confidential information or valuable intellectual property, or simply to compromise payment systems. Others use social engineering to infiltrate processes for a small number of large payments using one or more bank transfers.

The From field of an email is often spoofed to make the sender look like a well-known organization or domain, similar to yours or you're trusted partners. For example, the letter "o" can be replaced by the number "0" or the letter "w" by the letter "w" from the Russian alphabet.

Whereas previously phishing campaigns simply contained malicious documents attached to e-mail as-is or as a zip file, now criminals have improved their methods. Higby explains that many malicious documents are now hosted on legitimate sites like Box, Dropbox, OneDrive, or Google Drive because attackers know they are unlikely to be blocked by the IT department.

Total Security is stopping these types of phishing install total security antivirus. 

Comments

Popular posts from this blog

Why Not to Restart Your Computer if It Is Infected With the Ransomware | Total Security

What Is a Ransomware Virus and How Do You Protect Your Computer From It | Total Security

What is a zero-day threat? Free Antivirus Software