The New Phishing Threat
I’m sure many of you have received phishing email. Attackers seeking to comprise the credentials of your end-users have traditionally used the phishing method. Your business should have implemented things like Advanced Threat Protection (ATP), DomainKeys Identified Mail (DKIM), Domain-based Message Authentication, Reporting, and Conformance (DMARC), and more generally SPAM filtering.
These security elements all work together to eliminate spam and nefarious links or message attachments. Furthermore, these tools eliminate spoofing (ascribing the email to someone you know when it isn’t really them) and stop the reception of email from domains that aren’t trusted.
As more and more businesses have adopted these tools, threat actors have had to evolve. They always do. Message delivery is the key. They need to get the message in front of your end-user. Then, your end-user is required to make a decision. A larger email delivery rate results in a larger volume of decisions. A single bad decision can result in the loss of corporate Intellectual Property (IP) or the loss of access to it. It can also result in the loss of Personally Identifiable Information (PII) and can result in fines amounting to thousands or millions of dollars. More often than naught, it results in misleading financial transactions.
In the past, threat actors would register a new domain. Then, they would use the email systems associated with that domain to phish. As time went by, they wouldn’t create any random domain, they’d take your domain and add or delete the human doesn’t quickly detect. That’s where DKIM and DMARC got really good. Really good means, the threat actors are having message delivery issues. Their emails aren’t getting through the front gate because their newly created domain names aren’t passing the reputation test.
Today, they’re doing something more.
Threat actors will now leverage a proxy messaging system. What does that mean? They will register a domain that looks legitimate. Then, they will use a platform like Trello to issue emails. The Trello domain passes the domain reputation test, so their message gets through the front door and is delivered to your inbox. However, users are mostly trained to look at the sender of an email message. Trillo is a legit site so the link must be trustworthy right? Wrong! They’ve moved the nefarious payload or request to Trello. From there they accomplish the exact same thing without any embedded link or file being in their mail application.
The Threatscape is evolving daily. The cybersecurity position of your business MUST evolve with it. If your business is lagging in any area, your end-users aren’t just a target. They can unintentionally become a threat. At Auxzillium, we remain on the cutting edge of recommending, implementing, and managing the best cybersecurity controls. An Auxzillium assessment is the first step toward a peaceful night’s sleep.