Every week, an average of more than 700 pieces of malware is delivered
Email is how business gets done in the modern world. Despite its widespread use and security measures designed to thwart threats, email remains highly vulnerable to foul play. Organisations task IT professionals with weeding out spam, Trojan horses and virus-laden correspondence, but most security measures are more than a decade old. A fresh look needs to be taken at enterprise email security as the old mass email attacks fade into the shadows and new, more highly targeted attacks become all the rage with hackers who want access to precious data.
The Way We Were: Phishing
It used to be that a traditional mass email attack followed a tried-and-true model that relied on a shotgun approach called phishing. A high volume of email containing malware as an attachment or in the body of the email itself, were sent to untargeted recipients. Hackers would only get a small percentage of recipients to act on the email with this approach but, just like its namesake - the more lines you have in the water, the more likely you are to get a nibble. Perhaps this approach would have remained the preferred method for hackers, except for one problem: the fish wised up and stopped biting.
Users are now keen on recognizing these attacks. It would be ridiculous now for someone to expect that randomly, royalty from a faraway land chose them to protect their family's fortune. But this used to work on an embarrassingly high volume of people.
Along with smarter users, traditional email security solutions became very proficient at sniffing out these schemes by employing technologies such as:
- Sender email reputation to identify addresses that are known to spew out spam
- Lexical analysis to analyse email content that contains word combinations and patterns commonly found in spam
- Antivirus to help defend against known viruses that reside in email attachments
The Next Evolution of Attack: Spear-phishing
They call it spear-phishing. Most likely because if you knew what it really entailed, we would all be too scared to read our emails and get any work done. Spear-phishing is a low volume, highly targeted attack. No longer do emails make wild claims promising wealth, but instead they seem totally legitimate and the malware is delivered via an embedded URL within the email.
To craft these spear-phishing emails, hackers target specific recipients and gather information on them from social networking and public record websites. Then the hacker compromises a legitimate domain or server so their emails have a reputable address. Using the information they have learned about their target through research, hackers create a phishing email sent from that reputable address, which contains a message socially engineered to increase the likelihood of the target to click. When the target clicks on the embedded URL (which can also be linked to a legitimate, but compromised website) their computer downloads the malware. The malware does what malware is designed to do and looks for network vulnerabilities. It's a new approach but the end result is the same; confidential data is stolen and the target is changed to the victim.
No comments:
Post a Comment