Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Friday, 5 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Private Information Stored in Document Files Provides Most Popular Breach Target for Cyber Attackers

by The Gurus
October 13, 2016
in Editor's News
attack
Share on FacebookShare on Twitter

TopSpin Security, Inc., the leader in integrated deception and detection solutions, today announced the results of the Applying Deception Mechanisms for Detecting Sophisticated Cyber Attacks Report, a study investigating the performance of deception technologies in corporate environments. Professional hackers and security experts from across the globe participated in the research, which simultaneously included a variety of malware attacks.
The study revealed that private information stored in document files is the most popular target for attacks coming from professional hackers, as well as from malware. File traps, including Office files, recent docs and deleted docs, were touched the most accumulative times during the research. The next most attractive attack targets were application traps, consisting of session apps and browsers, followed by email traps. Notably, 100 percent of the attackers were detected during the initial stages of the attack during the study.
As far as trap types triggered by the hacker participants and malware, 90 percent of the application traps set were touched at least once, followed by 70 percent of the email traps and 64 percent of the document traps. However, it is interesting to note that the research revealed that human attackers and malware have very different targets they seek. While human attackers seek document files, malware and machine attacks target applications.
“This research is unique in gathering information about attack patterns of hacking experts and advanced malware, and the effectiveness of deception traps set in an enterprise,” said Omer Zohar, Head of Research at TopSpin Security. “Attackers go after files not only to steal them – but also in order to use information stored in files to get credentials and other types of data that helps them traverse through the network.”
For a copy of the study, see: https://www.topspinsec.com/portfolio-items/applying-deception-mechanisms-detecting-sophisticated-cyber-attacks/
Other key findings of the research include:

  • For the most popular traps triggered by human attackers, 77 percent of participants triggered document traps set in the enterprise environment. Next, 45 percent of the hackers triggered credential traps, consisting of usernames and passwords in files, directories and emails; followed by 36 percent who triggered email traps. In addition, human attackers also reached network, application and IoT-based traps.
  • When it comes to malware attacks, application traps were the most attractive, successfully luring malware 90 percent of the time. Next, malware triggered 25 percent of the beacon traps in the environment, mechanisms built into a document or email file which send signals to pre-defined servers every time the file is opened. The third most popular attack targets for malware were document traps, 13 percent of which were triggered by malware.
  • Passwords are the holy grail for attackers. The research showed that attackers not only picked up passwords regardless of their source (email, credman, lsass) or format (clear text, hashed, session ticket), they used the acquired passwords multiple times in a variety of locations. For example, attackers found an average of two credentials each, while each password was attempted an average of 2.5 times. In one instance, a password was used 11 times in 11 different places.

The Research Department at TopSpin Security conducted this study to investigate the efficiency of different deception technologies, as well as discover which other types of baits (decoys, mini-traps, beacon traps, “poisoned data”) attract which type of attackers. Overall more than 50 professional hackers and security experts used their knowledge and skills to try to extract a pre-defined piece of data and stay undetected. The month-long experiment was conducted as a Capture the Flag (CTF) challenge, and simultaneously the environment was tested against a variety of malware programs. The research sample called for the best experts in the field – red teams, pen testers and security researchers – to participate.
TopSpin administered the study using its DECOYnet™ deception solution. The types of traps deployed by DECOYnet included file traps (documents, beacon traps, emails, logs, databases and recent/deleted documents); application traps (session apps including SSH and FTD, browsers app uninstall information); network traps (network table caches poisoning such as ARP and NetBios, mounted IoT devices including printers and cameras, open and half open connections to other decoys, and host and ImHost files); and credential traps (password and hash injections, Windows Credentials Manager and password managers).
DECOYnet is the industry’s only deception-based solution with an integrated, full-fledged traffic analysis engine for continuously mapping organizations’ network and assets, and assessing vulnerabilities for better deception placement and adaptation to changes in organizations’ dynamic environments. Its powerful deception and egress analysis engines uniquely provide Intelligent Deception via strategically placed traps and decoys; Security Visibility detecting attackers’ communication channels and illuminating network blind-spots; and Threat Analysis, correlating data from both the deception and visibility layers for additional security and dropping false positive rates to virtually zero. DECOYnet is the only solution to offer fully automated, point-and-click configuration of traps and decoys.

ShareTweet
Previous Post

Majority of businesses have not inspected cloud services for malware

Next Post

Keep IoT A-OK – Hackers Capitalise on Software Vulnerabilities

Recent News

Frontline Workers Twice as Likely to Use Unapproved AI

Frontline Workers Twice as Likely to Use Unapproved AI

June 4, 2026
Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol