Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Please Do Not Feed the Phish

by The Gurus
April 19, 2018
in This Week's Gurus
Share on FacebookShare on Twitter

Adam Vincent, CEO, ThreatConnect

We’ve all heard the phishing attack stories that start with someone receiving an email that requests an urgent invoice review or password change and ends with a data breach where personal information is compromised, and money is lost. Although many of us may roll our eyes at the possibility of falling for such an obvious scam, we must acknowledge that if those tricks didn’t work, malicious actors wouldn’t keep trying.

Sometimes, previously established filters and phishing mailboxes aren’t enough. Vulnerabilities can still exist. At times, the content of an email can be troublesome. If a message asking for a money-wire transfer comes through looking urgent and legitimate enough, an unsuspecting employee might just take a requested action out of fear of repercussion. If an attachment looks innocent or a link seems harmless, it’s inevitable that someone might succumb. PhishMe reports that over 90 percent of data breaches can be traced back to phishing emails.

Phishing is often the initial step of a larger attack. Advanced persistent threat (APT) activity often leverages phishing emails as an initial intrusion method. Phishing provides actors with the ability to target specific individuals or organisations unlike other methods such as strategic web compromises. Even as organisations put their defences up against these attackers, the tactics continue to advance.

Another common tactic is to spoof URLs to appear similar to that of a legitimate organisation. This makes a link look trustworthy at first glance. For example – a full URL might be http://threatconnect.com.badguys[.]com, but unless the recipient looked closely and noticed that the domain was actually badguys[.]com, they might be fooled. Another domain spoofing technique involves registering domains with missing characters or subtle spelling errors, such as www.threatcomect[.]com which replaces two “n” characters with one “m” character. At a glance, the domain looks like it might be the legitimate ThreatConnect website, but upon closer examination it is clear that the characters aren’t quite right. This is a technique commonly used by many APTs including Fancy Bear, Deep Panda, and APT10.

Our ThreatConnect Research Team identified that was Fancy Bear most likely the threat actor responsible for the World Anti-Doping Agency (WADA) phishing incident that used this spoofing technique as well. Fancy Bear used domains such as wada-arna[.]org that were slightly misspelled in comparison to WADA’s legitimate wada-ama[.]org. The phishing emails using links to these domains likely were used in an attempt to harvest recipients’ credentials. By leveraging ThreatConnect and DomainTools, our team was able to identify an additional domain registered by the same individuals — tas-cass[.]org — that spoofs a domain for the Court of Arbitration for Sport, which works closely with WADA. . Taking a deeper look into spoofing and being on the lookout for domains spoofing your organisation can help your team prevent and mitigate similar incidents in the future.

When it comes to phishing, early detection and speedy incident response are imperative to prevent data breaches. Doing so can then help to establish filters so the offending email can’t make it to the intended recipients and phishing mailboxes to ingest the email into ThreatConnect for knowledge management, investigative, and research efforts. By proactively establishing these security measures, security teams can deter or monitor some of their threats that use these techniques.

However, email filters and phishing mailboxes aren’t fool proof, and if malicious emails get through those defences, recipients may have their guard down. Attackers are experts at creating phishing pages. In researching Fancy Bear activity targeting the DNC and the citizen journalism organisation Bellingcat, ThreatConnect researchers identified the use of Google-spoofing phishing emails and credential harvesting pages. In incidents where the malicious actor is attempting to harvest target credentials, this emphasises the importance of multi-factor authentication (MFA). In the worst-case scenario where a credential harvesting campaign successfully compromises an individual’s credentials, MFA mitigates the malicious actor’s ability to login to the given account.

It isn’t just large organisations that attackers go after. Small and medium sized companies aren’t safe just because of a smaller revenue stream. Since phishing attacks are relatively easy attacks to launch, its recommended that even the smallest teams be on the lookout for suspicious emails. When it comes to prevention and mitigation, one of the strongest defences any organisation can enable is automation. Establish a system that can evaluate and flag potential threats as they come in, and your security team will have the time to craft an effective response to the most pertinent threats.

Phishing attacks could be considered a “classic” example of cybercrime as we approach an era where we’re inundated with online danger. Although there is no one size fits all solution to preventing and mitigating phishing, security teams can save themselves time and stress by leveraging threat intelligence and establishing stronger filters. Teach your team to check URLs by hovering over them before clicking and always check with management before opening suspicious attachments. Spending that extra minute looking over any email you’re just not sure about and training employees to know what to look for when scrutinising messages could save your company a lot of time, energy, and money.

ShareTweet
Previous Post

DHS Funds Tech to Root Out Malware in Government Mobile Apps

Next Post

SANS Experts Share Five Most Dangerous New Attack Techniques

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol