Spray-and-pray tactics get an upgrade. MSPs face advanced phishing
Created: 2024-04-24 03:48:03
Cybercriminals leverage AceCryptor and Rescoms (RAT) to upgrade spam phishing messages difficult to recognize by both humans and machines. To defend, MSPs automate protection.
When cybersecurity experts and vendors describe phishing attacks, they usually split them into two big groups.
The first group consists of spam campaigns targeting a broad general audience with simple fraudulent messages. This approach has a low success rate but can be easily deployed en masse. The second group involves sophisticated attacks tailored for a specific person or group of people. This requires more time and planning; however, this effort pays off with higher success rates and/or other value that attackers derive.
But there are also attacks that stand somewhere in the middle and benefit from both approaches. For example, their fraudulent messaging is simple and can target broader audiences, but at the same time they are able to avoid the usual phishing red flags, largely because malicious email attachments are obfuscated with specialized tools.
ESET researchers documented such an attack when they discovered an email phishing campaign targeting European businesses.
Advanced phishing campaigns using AI and various evasion techniques are on the rise and can pose a challenge even for managed service providers (MSPs), which aim to deliver seamless IT services, including cybersecurity, to their customers while also keeping in mind their own protection. Risk from these types of campaigns are mounting because even the most focused employees may fall victim to malicious emails despite previous awareness training. Moreover, basic types of anti-phishing protection may be unable to detect these threats.
To address these risks, ESET has beefed up the prevention capabilities, incorporating advanced Anti-Malware, Antispam, and Anti-Phishing protection into ESET PROTECT, a formidable cyber threat prevention, detection, and response platform that MSPs can utilize. Having all these automated layers of protection in one service, ESET PROTECT minimizes the email attack surface, simultaneously reducing the complexity of subsequent security processes.
The most prevalent attack
Phishing doesn’t have to be simple
- All emails look like B2B offers for the victim companies.
- Email addresses used to send spam emails were imitating domains of other companies.
- Business email compromise (BEC) was involved in multiple campaigns — attackers abused previously compromised email accounts of other company employees to send spam emails.
- Attackers did their research and used existing companies and even existing employees’/owners’ names and contact information when they were signing those emails.
- The content of emails was in many cases quite elaborate.
Translated message:
Dear Sir,
I am Sylwester [redacted] from [redacted]. Your company was recommended to us by a business partner. Please quote the attached order list. Please also inform us about the payment terms.
We look forward to your response and further discussion.
--
Best Regards,
How to defend
- Anti-Spam technology filters spam messages with almost 100% accuracy.
- Anti-Phishing prevents users from accessing web pages known for phishing by parsing message bodies and subject lines to identify URLs. URLs are then compared against the phishing database and rules to determine the presence of a phishing attempt.
- Anti-malware scans email attachments to determine whether it is malicious, unknown, or safe.
- ESET’s in-product Sandbox assists in identifying the real behavior hidden underneath the surface of obfuscated malware.
- If ESET Mail Security is unsure of the potential threat, it can forward the attachment to the proactive cloud-based threat defense tool called ESET LiveGuard Advanced. It analyzes samples in a cloud sandbox, and then submits the result back to Mail Security within minutes.
- If the malicious attachment is opened, it will face ESET Endpoint Security monitoring and evaluating all executed applications based on their behavior and reputation. It is designed to detect and block suspicious processes.
Battling alert fatigue
Mastering vigilance without burnout
About ESET
ESET develops software solutions that deliver instant, comprehensive protection against evolving computer security threats. ESET pioneered and continues to lead the industry in proactive threat detection. ESET NOD32 Antivirus, its flagship product, consistently achieves the highest accolades in all types of comparative testing and is the foundational product that builds out the ESET product line to include ESET Smart Security. ESET Smart Security is an integrated antivirus, antispyware, antispam and personal firewall solution that combines accuracy, speed and an extremely small system footprint to create the most effective security solution in the industry. Both products have an extremely efficient code base that eliminates the unnecessary large size found in some solutions. This means faster scanning that doesn’t slow down computers or networks. Sold in more than 160 countries, ESET has worldwide production headquarters in Bratislava, SK and worldwide distribution headquarters in San Diego, U.S. ESET also has offices in Bristol, U.K.; Buenos Aires, AR; Prague, CZ; and is globally represented by an extensive partner network. For more information, visit our local office at https://eset.version-2.sg.
About Version 2 Limited
Version 2 Limited is one of the most dynamic IT companies in Asia. The Company develops and distributes IT products for Internet and IP-based networks, including communication systems, Internet software, security, network, and media products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 Limited offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which includes Global 1000 enterprises, regional listed companies, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities. For more information, please visit https://www.version-2.com.sg/ or call (65) 6296-4268.