Phishing is a form of fraud that involves impersonating a trusted institution or person (e.g., a bank, courier company or public figure) to persuade a victim to take action in order to benefit the attacker, such as providing login credentials. According to the 2021 annual report, CERT Poland handled as many as 22,575 phishing-related incidents, classifying this cyber threat as one of the most popular in 2021.
When talking about phishing, we often deal with mass mailing. However, there are several types of popular phishing out there, which are worth distinguishing:
Phishing attacks have evolved significantly over the past few years. They are no longer inane messages which are very different from genuine emails, while fraudulent website looks similar to the original one. What’s more, phishing messages are more and more often being used to send malware that can lead to ransomware attacks.
Currently, attackers use various techniques to hide their true intentions while creating phishing campaigns. These include browser-in-the-browser, homography attack or using trusted web pages to embed malware. Phishing also owes its popularity mainly to a large number of automated tools which can set up entire phishing campaigns – so you don’t need to be a developer or technology expert to create such a campaign. At the same time, in the so-called darknet, it is more and more common to find “Phishing as a Service”, that is websites where, for a subscription fee, we have access to many templates of popular sites or fake payment gateways, allowing us to phish for e.g., BLIK codes. With a subscription, we also get domains on which the entire infrastructure required is automatically set up.
‘I believe in the next few years the popularity of phishing will increase even more. Looking at today’s techniques, I can say that unless we regularly educate our employees and keep our systems secure, we may reach a situation which makes us very vulnerable to all sorts of attacks.’
Michał Błaszczak, Pentester EmailLabs
What needs to be remembered, however, is that phishing is not limited to email messages only. There is also Vishing or Voice Phishing, in which scammer call us (often impersonating bank operators) to trick us into revealing personal information, and Smishing or phishing via text message.
Apart from traditional phishing, criminals are often using smishing, the above-mentioned phishing via SMS. Since it’s not a problem to impersonate a particular service provider, cyber attackers are using it as another way to spread fake websites or malware. The rules behind this attack are the same as for classic phishing. The offender tries to influence us with certain emotions and thus force us to enter a given website address. There are cases in which this cybercriminals are so confident they don’t even impersonate specific service providers and send messages from ‘normal’ phone numbers. One would think that nobody would read such a message, however, the reality is far from that.
As I mentioned earlier, phishing has evolved strongly in recent years and attackers no longer limit themselves to creating a similar email address. So in this part of the article, we’ll have a closer look at some of the tactics used in ‘today’s’ phishing:
This technique displays an allegedly new window within a visited browser website, which simulates a fake login panel. In fact, that window is actually a page element, so the visible address of the new window is a plain text controlled 100% by the attacker. As a result, users may believe they are logging from a real website, especially since nowadays signing-in via third party services, e.g. Facebook, Twitter, Github, is nothing new (for such logins, we may see a ‘pop-up’ window asking to sign-in). The easiest way to recognize such attacks is to try to ‘pull’ the new window out of the web page we are on. If we fail to do so, we can be sure a Browser in the Browser technique has been used to attack us.
source: https://github.com/mrd0x
It’ an attack which takes advantage to create and display URLs that include characters from non-Latin alphabet. Since different alphabets can have very similar characters, it can be used to build a nearly identical URL for a phishing attack.
Well-known link shorteners work in a rather simple and familiar way, however, it’s worth noting that there are shorteners much more sophisticated than the ones we know. That’s because some of them are able to trick websites which ‘expand’ links, letting us know if a particular shortened URL really leads to, e.g. a bank web page. Besides, such shorteners are able to redirect users to different pages based on a device which the link is opened on, so the attack can be more targeted and harder to detect.
Cybercriminals are increasingly using popular and thus, trusted websites for conducting i.a., phishing attacks. By taking advantage of such pages, attackers effectively lull victims into a false sense of security. As part of this technique, they embed malicious files in familiar sites or create fake login pages. A full list of such websites can be found at Lots Project.
The increasing number of phishing attacks each year, and the projection that this trend will continue to escalate, aren’t likely to astonish anyone. This can be attributed, in part,...
With the emergence of the Covid-19 pandemic, many brands have been challenged to adapt in a short period to the changed reality and new consumer attitudes. That meant reorganizing...
If you’re sending more than 5,000 emails a day, you need to pay attention. Microsoft just dropped a major announcement that’s going to change how your emails get delivered....
Best practices, Email Authentication
Email headers may seem like a cloud of confusion, but fear not! In this ultimate guide, we will break down email headers and make them crystal clear. We’ll start...
Does your inbox feel like a never-ending to-do list? Are you spending more time sorting emails than actually working? You’re not alone. Millions of professionals struggle with email overload,...
We are delighted to announce that Vercom S.A., the company behind the EmailLabs project, has successfully completed the ISO 22301 certification process. This significant achievement underscores our commitment to...
EmailLabs, as part of the Vercom group, proudly announces its full commitment to aligning its ICT services with the latest cybersecurity standards. In response to dynamically changing regulations, the...
Best practices, Compliance & Security
As we step closer to a digitally connected future, ensuring inclusivity in our marketing strategies is more important than ever. Email, a cornerstone of digital communication, must evolve to...
We are pleased to announce that MessageFlow, a product from the Vercom S.A. group, has received the prestigious CSA (Certified Senders Alliance) Certification. This recognition not only underscores the...
The increasing number of phishing attacks each year, and the projection that this trend will continue to escalate, aren’t likely to astonish anyone. This can be attributed, in part,...
With the emergence of the Covid-19 pandemic, many brands have been challenged to adapt in a short period to the changed reality and new consumer attitudes. That meant reorganizing...
If you’re sending more than 5,000 emails a day, you need to pay attention. Microsoft just dropped a major announcement that’s going to change how your emails get delivered....
Best practices, Email Authentication
Email headers may seem like a cloud of confusion, but fear not! In this ultimate guide, we will break down email headers and make them crystal clear. We’ll start...
Does your inbox feel like a never-ending to-do list? Are you spending more time sorting emails than actually working? You’re not alone. Millions of professionals struggle with email overload,...
We are delighted to announce that Vercom S.A., the company behind the EmailLabs project, has successfully completed the ISO 22301 certification process. This significant achievement underscores our commitment to...
EmailLabs, as part of the Vercom group, proudly announces its full commitment to aligning its ICT services with the latest cybersecurity standards. In response to dynamically changing regulations, the...
Best practices, Compliance & Security
As we step closer to a digitally connected future, ensuring inclusivity in our marketing strategies is more important than ever. Email, a cornerstone of digital communication, must evolve to...
We are pleased to announce that MessageFlow, a product from the Vercom S.A. group, has received the prestigious CSA (Certified Senders Alliance) Certification. This recognition not only underscores the...
The increasing number of phishing attacks each year, and the projection that this trend will continue to escalate, aren’t likely to astonish anyone. This can be attributed, in part,...
We are delighted to announce that Vercom S.A., the company behind the EmailLabs project, has successfully completed the ISO 22301 certification process. This significant achievement underscores our commitment to...
Do you ever wonder how many people actually open the emails you send? Knowing the number of people who open your emails is essential for understanding the effectiveness of...
Gmail has become a cornerstone of modern email communication, offering a dynamic platform that caters to both personal and professional needs. Since its inception in 2004, Gmail has consistently...
EmailLabs, as part of the Vercom group, proudly announces its full commitment to aligning its ICT services with the latest cybersecurity standards. In response to dynamically changing regulations, the...
Email deliverability is a cornerstone of effective digital marketing. It ensures that your carefully crafted messages reach the intended recipients’ inboxes rather than being relegated to spam folders. Google...
If you’re sending more than 5,000 emails a day, you need to pay attention. Microsoft just dropped a major announcement that’s going to change how your emails get delivered....
Best practices, Email Authentication
Email headers may seem like a cloud of confusion, but fear not! In this ultimate guide, we will break down email headers and make them crystal clear. We’ll start...
Does your inbox feel like a never-ending to-do list? Are you spending more time sorting emails than actually working? You’re not alone. Millions of professionals struggle with email overload,...
Apple Mail, Email Marketing, Gmail
Efficient email management has become a necessity in today’s digital world. To address this need, email services categorize incoming messages into different tabs or folders, helping users streamline their...
We are delighted to announce that Vercom S.A., the company behind the EmailLabs project, has successfully completed the ISO 22301 certification process. This significant achievement underscores our commitment to...
Do you ever wonder how many people actually open the emails you send? Knowing the number of people who open your emails is essential for understanding the effectiveness of...
Gmail has become a cornerstone of modern email communication, offering a dynamic platform that caters to both personal and professional needs. Since its inception in 2004, Gmail has consistently...
EmailLabs, as part of the Vercom group, proudly announces its full commitment to aligning its ICT services with the latest cybersecurity standards. In response to dynamically changing regulations, the...
Email deliverability is a cornerstone of effective digital marketing. It ensures that your carefully crafted messages reach the intended recipients’ inboxes rather than being relegated to spam folders. Google...
If you’re sending more than 5,000 emails a day, you need to pay attention. Microsoft just dropped a major announcement that’s going to change how your emails get delivered....
Best practices, Email Authentication
Email headers may seem like a cloud of confusion, but fear not! In this ultimate guide, we will break down email headers and make them crystal clear. We’ll start...
Does your inbox feel like a never-ending to-do list? Are you spending more time sorting emails than actually working? You’re not alone. Millions of professionals struggle with email overload,...
Apple Mail, Email Marketing, Gmail
Efficient email management has become a necessity in today’s digital world. To address this need, email services categorize incoming messages into different tabs or folders, helping users streamline their...
We are delighted to announce that Vercom S.A., the company behind the EmailLabs project, has successfully completed the ISO 22301 certification process. This significant achievement underscores our commitment to...