Phishing seems old hat, an archaic cyberattack method that only the uninitiated would fall for.
But evolving, ever-more sophisticated and realistic phishing methods continue to lure the unsuspecting — and remain one of the most successful avenues for threat actors.
Why?
“Simply because it’s effective,” said Brett Winterford, regional CSO for Asia Pacific and Japan at identity access management company Okta. “There isn’t a universal control for protection against social engineering.”
Not just enticing subject linesPhishing dates to the late 1990s when the internet was really just gaining mainstream traction. And, while it all started with emails — “Click this link to secure your account!” “Update your login credentials!” — today’s attackers are using sneakier, far more advanced methods.
For instance, according to cloud security company Netskope, users are increasingly being tricked by fake third-party cloud apps. Attackers have created apps that mimic legitimate, widely-used ones such as Microsoft or Google 365 — but, say, the login is just slightly off color or shape — that convince users to enter their credentials.
Another popular tactic is using custom domains to host phishing sites. This tactic allows attackers to craft URLs that, again, closely resemble legitimate domains. Other methods include redirection services and URL shorteners, as well as search engine referrals.
Attackers are “weaponizing data voids,” according to Netskope researchers, by creating pages around uncommon search terms (such as product manuals and using specific features in specific software).
And in social media, attackers use pop-up surveys, direct messages, videos, pictures and comments linking to phishing sites.
All this makes phishing a major threat to enterprises, even today. Per Proofpoint’s annual State of the Phish Report, 84% of organizations had at least one successful phishing attack in 2022 and 54% faced three or more. Furthermore, the direct financial loss from successful attacks increased by 76% last year.
Commoditization of cybercrimeA newer, even more troubling cyberattack method is adversary-in-the-middle (AitM) phishing, said Winterford. As he detailed in a recent blog post, this directs targets to a malicious website configured as a reverse proxy server. Real-time phishing sites relay requests between the user and an impersonated web app. If the user is successfully tricked into signing in, attackers can access credentials and session tokens.
While this method has typically been reserved for targeted attacks, the increased use of phishing-as-a-service (PaaS) has made capabilities available to a “far larger set of threat actors,” said Winterford.
PaaS tools — including EvilProxy, NakedPages and, more recently, Greatness — lease access to infrastructure, configuration and phishing templates required to operate AitM campaigns.
“Things such as ‘phishing-as-a-service’ are designed to allow non-technical or less technical bad actors to get in on the cybercrime game,” commented Erich Kron, security awareness advocate at KnowBe4.
By leaving infrastructure maintenance and malware development to those with the technical skills, cybercriminals can concentrate on enticing people to click links or open documents.
It’s a lucrative market, he said, and attractive to many people “who could not handle all of the parts needed to successfully phish people on their own.”
The economics of cybercrime are fascinating, Winterford said, noting that over the past few years, Okta researchers have seen “greater work specialization.” That is, a relatively small number of highly-skilled actors focus on exploit development, a larger set focuses on gaining initial access to networks, and many others buy and profit from that access (deploying ransomware, stealing data for extortion or compromising business email).
“This creates a supercharged environment that rewards adversary innovation,” he said, “and punishes organizations that rely on highly complex, legacy approaches to identity in which users on the corporate network are assumed to be trusted.”
Impacts of artificial intelligenceAI informs nearly all enterprise discussions these days and, of course, cybersecurity is no outlier. AI is capable of creating “more convincing phishing lures or more precise targeting,” said Winterford.
“In an AI-augmented world, we’ll need to provide methods of access in which users aren’t expected to distinguish between what is benign and what is malicious,” he contended.
Whether AI-generated or not, the vast majority of social engineering attacks are avoidable, he said, suggesting that phishing-resistant authenticators are the best option. These are passwordless sign-in methods in which the authenticator is “cryptographically bound” to a service during enrollment.
Furthermore, he said, the primary control for phishing attacks that deliver a malware payload are endpoint protection and execution control (application whitelisting) tools.
He pointed out that traditional multifactor authentication (MFA) tools based on OTPs (one-time passcodes) do offer a degree of protection, but often can’t distinguish whether the domain the user is sharing credentials with is legitimate or malicious.
Beyond fighting phishing, it is important to evaluate risk in real time that considers a number of signals such as user behavior during sign-in, he added. Risk levels can be used to determine whether to allow or deny access, prompt for additional MFA or allow passwordless authentication.
“The traditional perimeter-driven security model doesn’t fit today’s business environment,” said Winterford. “Today’s workforce often includes remote workers, contractors and business partners that require access to a range of cloud-based applications.”
Ultimately, as he put it, “identity is now the new perimeter.”
Practice defense-in-depthEven with advanced MFA in place, though, organizations need to “practice defense-in-depth,” said Winterford. It is important that users be trained to identify indicators of suspicious messages, phishing sites and other social engineering tradecraft and understand where to report suspicious activity.
“Resilience relies on both effective technology controls and thoughtful business processes,” he said.
Security teams should also create policies that educate users about the difference between using public generative AI models that are available “as-a-service,” versus models that are owned and managed within an enterprise.
Comments