Threat intelligence firm Group-IB says cybercriminals actively used Google Forms and Telegram bots to collect stolen data from exploit kits during phishing attacks.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Phishing websites are increasingly more deceptive but AI can utilize computer vision to ensure pages that would otherwise deceive end-users are detected and stopped in their tracks.
The fact that phishing attacks have been on the rise is no secret. One of the most interesting developments is that malicious emails are now being timed to coincide with the "mid-afternoon slump" common to office workers.
According to the Phishing Activity Trends Report by the Anti-Phishing Working Group (APWG), phishing attacks surpassed one million for the first time in three months in the first quarter of 2022.
The most recent Microsoft Security Intelligence Report indicates that phishing attacks are now by far the most frequent threat to the cyber landscape, increasing a massive 250% since the previous report.
Recent study by Imperva gets under the skin of what can now be characterized as an increasingly complex and rapidly maturing phishing industry. The study examined more than 1,000 free phishing kits that allow for the development of phishing web sites in what has been called an ‘easy to deploy’ format.
Study shows effects of phishing awareness training starts to wear off after four months and many employees will have lost what they learned almost entirely after six months.
The embassy phishing campaign is just one element of a rash of recent activity by the Russian hackers referred to as APT 29, probably better known to the general public as Cozy Bear.
Researchers have discovered a new phishing campaign leveraging Facebook posts to bypass email security and steal users' account credentials and personal information.
At ANY.RUN malware analysis sandbox, we noticed an increase in phishing scams that direct users to fake Microsoft Outlook login pages, collecting confidential credentials. We decided to analyze one such campaign.










