Types of Phishing Attacks and How to Detect Them
Types and Tools of Phishing, the Problem of Targeted Attacks, Examples Of letters and Phishing Prevention
Virtually every data breach and all online attacks today involve
some form of a phishing attempt to steal passwords, launch fraudulent
transactions, or trick the recipient of a message into downloading malicious
software. According to PhishMe, in early 2016, 93% of phishing emails were
delivered using ransomware.
Security experts regularly remind users to watch out for
phishing attacks, but many simply don't know how to recognize them as attacks
can take many forms. “Phishing attacks come in many different forms,
targeting specific individuals in an organization who have access to sensitive
data” comments Shalab Mohan of Area 1 Security.
Users tend to be poor at recognizing the actions of
fraudsters. According to Verizon's cybersecurity report, an attacker who
sends 10 phishing emails has a 90 percent chance of one person being
trapped. This seems absurd at first, but only when it comes to technology
users, not manufacturing or education users. Add to that the fact that not
all phishing emails work the same: some are regular emails and others are
carefully designed to target a specific type of people, and it becomes
increasingly difficult to teach users to be careful when the message seems a
little strange.
Let's take a look at the different types of phishing attacks and
how to recognize them.
What is Phishing
Phishing is the mass distribution of emails. The most common form of phishing is bulk email, where someone sends an email
impersonating someone else and tries to trick the recipient into performing
actions that usually involve logging in to a website or downloading
malware. Attacks are often based on email spoofing, where the email
header, the From field, is spoofed to make the message look as if it was sent
to someone the recipient trusts.
What can happen if you still mistake a phishing email for a real
one?
1.
After receiving a
letter from a supposed acquaintance, you can follow a dangerous link or
download a file containing a malicious program. It can cause significant
damage.
2.
If the scammers
convince you of the truth of their story, it is possible that you will want to
transfer money to them. So you can lose even a large amount.
3.
You can send your
financial data or work files to attackers. This will lead to the loss of
your personal or company funds, and therefore to problems at work.
4.
Under the guise of
your acquaintances, scammers can get into your confidence and use whatever they
can find out from you for extortion.
What You Should Pay Attention to
Be wary if you see a call to enter any of your data - in the
letter itself, by reference or in any other way. None of the services you
use will ever ask for your data, they are already in the system. However,
attackers may well send a letter like the one shown in
Another example of a phishing email is shown in Figure 2. Notice
how the text is composed. It contains a direct indication that your
profile will be blocked if you do not follow the instructions contained in the
letter. This is manipulation and a clear sign that the letter was written
by scammers.
|
Phishing email |
However, phishing attacks don't always look like a UPS delivery
notification email, or a warning message from PayPal about password expiration,
or an Office 365 email about storage quotas. Some attacks target
organizations and individuals specifically, while others use methods other than
email.
Business email compromise
In addition to massive, widespread phishing campaigns, criminals
target key individuals in the finance and accounting departments through email
fraud, business email compromise (BEC), and CEO email manipulation. By
posing as financial officials and CEOs, these criminals try to trick victims
into transferring money to unauthorized accounts.
Typically, attackers compromise a manager's or CFO's email
account using various methods. The fraudster secretly monitors the email
activity of the manager for a certain period in order to find out about the
processes taking place in the company. The actual attack takes the form of
a fake email that looks like it came from a compromised manager's account and
is sent to whoever is the regular recipient of such emails. The letter
appears to be important and urgent and requires the recipient to send a bank
transfer to an external or unfamiliar bank account. The money eventually
ends up in the attacker's bank account.
According to the FBI's Internet Crime Complaints Center,
fraudulent activities such as the BEC have resulted in actual losses of over $
4.5 billion and are a global problem. An example of such a letter is shown
in Figure 3. Notice that the letter indicates a high priority task. This
may well be a manipulation thought out by an attacker. Regardless of the
way the letter is worded, if it involves the implementation of actions that are
dangerous to your company or reputation, it should be ignored.
|
. An example of a BEC attack |
Remember that the following actions are considered dangerous:
·
sending data;
·
sending money;
·
following a link;
·
opening an attachment;
·
installing the
application;
·
following the link to
the site, followed by registration with an account (by entering a username and
password).
The Problem of Targeted Attacks
Spear-phishing attacks are the process of sending emails to
specific recipients on behalf of a supposedly safe sender. The goal is to
infect devices with malware or convince the victim to transfer information or
money. Phishing attacks began as a scam to obtain money from
"Nigerian princes" in the mid-1990s. They have now evolved into
effective, well-designed, and targeted campaigns.
Phishing targeted attacks get their name from the fact that
scammers catch random victims using fake or fraudulent email as
bait. Using targeted phishing attacks, attackers target victims, and
high-value organizations. Instead of trying to get 1,000 consumers' bank
credentials, it may be more profitable for a fraudster to target multiple
businesses.
In a recent phishing campaign, Group 74 (also known as Soft, APT28, Fancy Bear) targeted cybersecurity professionals. An email was written purportedly related to the Cyber Conflict US conference and events organized by the United States Military Academy Army Cyber Institute, NATO Cooperative Cyber Military Academy, and NATO Cooperative Cyber Defense Center of Excellence. Although CyCon is a real conference, the attachment was a document containing a malicious Visual Basic for Applications (VBA) macro that downloaded and ran malware intelligence software called Seduploader.
What is the fundamental difference between phishing attacks and
spear-phishing attacks? While conventional phishing campaigns have a large
number of targets with relatively low performance, spear-phishing is a targeted
attack using emails crafted specifically for the intended victim.
"Phishing is a typical low-tech attack," said Aaron
Higby, co-founder, and CTO of anti-phishing firm Cofense, formerly known as
PhishMe. - Attackers don't really care who their target is. They just
use a large net trying to catch as many fish as possible. Spear phishing
is a campaign that is purposefully built to penetrate one organization,
preceded by a study of names and processes within the company. "
If mass phishing primarily involves the use of off-the-shelf
automated kits for mass credential collection using fake login pages for
regular banking or postal services or distributing ransomware or encryption
malware, then targeted phishing attacks are more complex. Some targeted
campaigns use documents containing malware or website links to steal
credentials in order to obtain confidential information or valuable
intellectual property, or simply to compromise payment systems. Others use
social engineering to infiltrate processes for a small number of large payments
using one or more bank transfers.
The From field of an email is often spoofed to make the sender
look like a well-known organization or domain, similar to yours or you're trusted
partners. For example, the letter "o" can be replaced by the
number "0" or the letter "w" by the letter "w"
from the Russian alphabet.
Whereas previously phishing campaigns simply contained malicious documents attached to e-mail as-is or as a zip file, now criminals have improved their methods. Higby explains that many malicious documents are now hosted on legitimate sites like Box, Dropbox, OneDrive, or Google Drive because attackers know they are unlikely to be blocked by the IT department.
Total Security is stopping these types of phishing install total security antivirus.

Comments
Post a Comment