Linchakin

IBM: ”Phishing Is A Popular Cybercrime Attack Vector”

 October 11, 2021     No comments   

Phishing is a Popular CybercrimeResearchers at IBM describe how criminals use phishing kits to launch widespread phishing campaigns with minimal effort. Phishing kits are software products that automate the process of setting up spoofed websites and handling email campaigns.

“The majority of phishing sites we see in our day-to-day analysis originate from phishing kits that are available for purchase on the dark web and are being reused by many different actors,” the researchers write. “Typical kits are professionally written and can contain thousands of lines of code. They can be configurable based on the campaign and even have proper error reporting. These kits range in price from a few hundred to a few thousand dollars and can be deployed in a matter of minutes. Conversely, malware attacks change all the time, shifting tactics around for all aspects, especially the underlying code.”

The criminals usually buy cheap domains to host their phishing sites, though they can spend more money to gain access to more resilient infrastructure.

“In most of the attacks we observe, phishers register cheap domains for malicious use, host attacks on a compromised domain or a combination of both,” the researchers write. “Some domain registrations are easy to fund, and this does not require exploiting or compromising an existing site. The downside is that it’s easier to detect and block a standalone malicious site versus an attack hosted on an established legitimate one. Dark web vendors who play in the phishing game sell access to compromised servers, but this option does raise the overall cost of the attack.”

Attackers can also buy lists of target email addresses that have been collected from data breaches and other sources.

“Once the phishing attack is ready, it has to get in front of potential victims,” the researchers write. “To send it out to the right audience, phishers can either contract an underground service that specializes in spamming, or they can go ahead and buy their own target lists. Target lists can be specific to a region or a language and can help attackers get into inboxes of webmail providers and company emails alike. Depending on the viability of the data and its contents, email lists can go for $50 to $500. The price is offset by the reuse of the same list for other attacks or reselling it to other criminals.”

New-school security awareness training with simulated phishing emails can enable your employees to thwart these attacks.

SecurityIntelligence has the story.

Adblock test (Why?)


You may be interested in:
>> Is a Chromebook worth replacing a Windows laptop?
>> Find out in detail the outstanding features of Google Pixel 4a
>> Top 7 best earbuds you should not miss

Related Posts:
>> Recognizing 12 Basic Body Shapes To Choose Better Clothes
>>Ranking the 10 most used smart technology devices
>> Top 5+ Best E-readers: Compact & Convenient Pen
  • Share This:  
  •  Facebook
  •  Twitter
  •  Google+
  •  Stumble
  •  Digg
Email ThisBlogThis!Share to XShare to Facebook

Related Posts:

  • GameStop confirms Black Friday PS5 and Xbox Series X restockPS5 and Xbox Series X restock may be hitting GameStop this weekGameStop has been offering a wide range of Black Friday deals this week, but it’s saved its best promotion for Thanksgiving day. While it’s not techni… Read More
  • FBI: Cyber Attacks Target Organizations Involved in Mergers and AcquisitionsA new notification from the FBI warns organizations of attacks at the perfect time when organizations are spending money, new people are being introdu… Read More
  • Phishing Attacks Impersonating Amazon Continue, Raising Concerns on the Cusp of Black Friday and the HolidaysNew phishing attacks in the form of impersonated Amazon order confirmation emails cause potential victims to make phone calls and give up credit card … Read More
  • Email Classified as ‘Malicious’ by Employees Has Increased by 35% in the Last YearNew data shows Phishing, Vishing, Social Media attacks, and Microsoft 365 credential attacks are all on the rise as more users are demonstrating savvi… Read More
  • Apple Black Friday deals 2021$159 AirPods Pro, $729 MacBook Air and more Apple Black Friday deals are here and going strong. And that means there are plenty of Black Friday deals on Apple products to be had, whether you're… Read More
Newer Post Older Post Home

0 Comments:

Post a Comment


Copyright © 2025 Linchakin | Powered by Blogger
Design by Hardeep Asrani | Blogger Theme by NewBloggerThemes.com | Distributed By Gooyaabi Templates