What Is Phishing? How Does This Cyber Attack Work And How To Prevent It

What Is Phishing? How Does This Cyber Attack Work And How To Prevent It


Definition of phishing

The goal is to trick the email recipient into believing the message is something they want or need - a request from the bank, for example, or a note from someone in their company - and to click on a link or download an attachment.


What really defines phishing is the form the message takes: Attackers masquerade as a trusted entity of some kind, often a real or real person, or company the victim might do business with. It is one of the oldest types of cyberattacks, dating back to the 1990s, and it remains one of the most prevalent and malicious attacks, as phishing messages and techniques are becoming increasingly sophisticated.


The word “Phish” is pronounced exactly as it is spelled, ie like the word “fish” - the analogy is that the fisherman throws a hook with bait there (phishing email) and hopes to bite. The term originated in the mid-1990s among hackers to trick AOL users into giving away their login information. 


Nearly a third of all violations in the past year involved phishing, according to Verizon's 2019 Data Breach Investigation Report. For cyber espionage attacks, that number jumps to 78%. The worst phishing news for 2019 is that its perpetrators are getting much better at it thanks to ready-made and well-produced tools and templates.


What is a phishing group?

The availability of phishing groups makes it easy for cybercriminals, even those with minimal technical skills, to launch phishing campaigns. The Phishing Toolkit brings together phishing sites' resources and tools that only need to be installed on the server. Once installed, all the attacker needs are to send emails to potential victims. Phishing groups, as well as mailing lists, are available on the dark web. Two sites, Phishtank and OpenPhish, maintain mass lists of well-known phishing groups.


Some phishing groups allow attackers to impersonate trusted brands, which increases the chances that someone will click on a fraudulent link. Akamai's search presented in the Phishing report - Baiting the Hook found 62 varieties for Microsoft, 14 for PayPal, seven for DHL, and 11 for Dropbox.


Duo Labs' report, Phish in a Barrel, includes a phishing cluster reuse analysis. Of the 3,200 phishing groups detected by Duo, 900 (27%) were found in more than one host. However, this number may actually be higher. “Why don't we see a higher percentage of group reuse? Perhaps because we were measuring based on the SHA1 segmentation of the group's contents. Jordan Wright, Duo's chief research and development engineer and author of the report, said a single change to only one file in the set would appear as two separate groups even when they are identical.


Anatomy of phishing tools [infographic by Duo Security]Dual security

Analyzing phishing groups allows security teams to track who is using them. “One of the most helpful things we can learn from analyzing phishing groups is where to send the credentials. By tracking email addresses present in phishing groups, we can link actors to specific campaigns and even specific groups, ”Wright said in the report. “It gets better. Not only can we see where the credentials are sent, but we also see where the credentials claim to be sent. Typically, creators of phishing groups use the address “from” as the signature card, which allows us to find multiple groups created by the same author.


Types of phishing

If phishing attacks have one thing in common, it is camouflage. Attackers impersonate their email address so that it appears to be from someone else, create fake websites that resemble the one that the victim trusts, and use foreign character sets to mask URLs.


However, there are a variety of techniques that fall under the phishing umbrella. There are two different ways to divide attacks into classes. One of the purposes of trying phishing. In general, a phishing campaign attempts to get the victim to do one of two things:


Handing over sensitive information. These messages are intended to trick the user into revealing important data - often a username and password that an attacker can use to compromise a system or account. The classic version of this scam involves sending an email designed to look like a letter from a major bank; By sending spam to millions of people, the attackers are ensuring that at least some of the recipients will be customers of that bank. The victim clicks a link in the message and goes to a malicious site designed to resemble a bank's web page, and then enters a username and password. The attacker can now access the victim's account.

Download malware. Much like spam, these types of phishing emails aim to make the victim infect their computers with malware. Often the messages are "lightly targeted" - they might be sent to an HR employee with an attachment claiming to be a job seeker resume, for example. Often these attachments are .zip files or Microsoft Office documents that contain embedded malicious code. The most common form of malicious code is ransomware - in 2017, it was estimated that 93% of phishing emails contain ransomware attachments.

As we indicated, sometimes they are not targeted at all; Emails are being sent out to millions of potential victims to try to trick them into logging into fake versions of very popular websites. Iron scales has counted the most popular brands that hackers use in their phishing attempts.


Other times, attackers may send "easily targeted" email messages to someone who plays a certain role in an organization, even if they know nothing about them personally. Some phishing attacks are aimed at obtaining or damaging login information from specific people's computers. The attackers devote more energy to deceiving these victims, who are chosen because the potential rewards are very high.


Spear phishing


When attackers try to craft a message to attract a specific individual, this is called spear phishing. (Photo of a fisherman aiming at a specific fish, rather than just throwing a hook into the water to see who bites.) Phishers define their targets (sometimes using the information on sites like LinkedIn) and use phishing addresses to send emails that can appear to come from co-workers. For example, a spear scammer might target someone in the financial department and pretend to be the victim's manager and request a large bank transfer in a short time.


Whaling


Whale hunting, or whaling, is a form of spear phishing that targets very large fish - CEOs or other high-value targets. Many of these frauds target company directors, who are considered particularly vulnerable: they have a great deal of power within the company, but since they are not full-time employees, they often use personal email addresses for work-related correspondence, which has no protection. Provided by the company email.


Gathering enough information to deceive a truly high-value target can take time, but it can pay off surprisingly high. In 2008, cybercriminals targeted corporate executives with emails claiming that FBI subpoenas were attached. In fact, they downloaded keyloggers on executives' computers - and the fraudsters had a 10% success rate, infecting nearly 2,000 victims.


Other types of phishing include phishing clones, phishing, and snowshoeing. This article explains the differences between the different types of phishing attacks.


Why does trolling increase during a crisis

Criminals rely on deception and creating a sense of urgency to succeed in their phishing campaigns. Crises like the coronavirus pandemic give these criminals ample opportunity to lure victims to take a bit of phishing.


During a crisis, people are on the edge of a precipice. They want information and are looking for guidance from employers, the government, and other relevant authorities. Email that appears to be from one of these entities and promises new information or directs recipients to complete a task quickly is likely to receive less scrutiny than it was before the crisis. An impulsive click later, and the victim's device is hit or the account is hacked.


The following screenshot is a phishing campaign detected by Mimecast trying to steal the login credentials of the victim's Microsoft OneDrive account. The attacker knew that with more people working from home, sharing documents via OneDrive would be commonplace.


The next two screens are from the phishing campaigns identified by Proofpoint. The first requires victims to download an app on their devices to "run a treatment simulation" for COVID-19. The app, of course, is malware. The second message appears to be coming from Public Health Canada and asking recipients to click on a link to read an important message. The link goes to a malicious document.


A malicious phishing home email with a malware link Proof point

Fake Public Health Agency Canada Temptation Proof point

How to prevent phishing

The best way to learn to spot phishing emails is to study examples captured in the wild! This Cyren webinar starts with a look at a real phishing website, disguised as a PayPal login, to entice victims to hand in their credentials. Check out the first minute or so of the video to see phishing site flags.


More examples can be found on the website managed by Lehigh University's Department of Technology Services where they maintain a gallery of recent phishing emails that students and staff receive.


There are also several steps you can take and the mindsets you should follow that keep you from becoming a statistic for phishing, including:


Always verify that the URLs are written in email links before clicking or entering sensitive information

Watch out for URL redirects, as they subtly send you to a different website with an identical design

If you receive an email from a source you know but which appears to be suspicious, contact that source with a new email, instead of just pressing Reply

Do not post personal data, such as your birthday, vacation plans, address, or phone number, publicly on social media.

These are the most clicked phishing scams according to a Q2 2018 report from KnowBe4 security awareness training company.

If you work in your company's IT security department, you can take proactive measures to protect the organization, including:


"Sandbox" for incoming email, verifying the security of every link the user clicks

Scan and analyze web traffic

A pen test for your organization to find weaknesses and use the results to educate employees

Reward good behavior, perhaps by displaying "problem of the day" if someone detects a phishing email

Antivirus to defends you from phishing,

Comments

Popular posts from this blog

Why Not to Restart Your Computer if It Is Infected With the Ransomware | Total Security

What Is a Ransomware Virus and How Do You Protect Your Computer From It | Total Security

What is a zero-day threat? Free Antivirus Software