Ten minutes was all it took for attackers to prey on an unsuspecting IT worker and gain access to the personal information — names, driver’s licenses, passports, even Social Security numbers — of an undisclosed number of MGM Resort customers.

Theoretically, when remote access is locked down and a system is patched against known vulnerabilities, it should be pretty sound — but this is where human fallacy comes into play.

One of the easiest ways for adversaries to access a system is through its users, making social engineering an increasingly enticing (and lucrative) tactic for threat actors, as further confirmed today by Netskope’s newest Cloud and Threat Report.

“Social engineering techniques have continued to be a mainstay of the adversary playbook,” the report’s authors write.

However, “social engineering isn’t limited to initial access. Adversaries also depend on users to execute malicious payloads that provide clandestine remote access, steal sensitive information or deploy ransomware.”

Spearphishing a go-to tactic

The new report analyzes the tactics most commonly used against Netskope customers in the first nine months of 2023. These include techniques for initial access, execution (running of malicious code), command and control (communicating with compromised systems) and exfiltration (stealing information).

By far, spearphishing links and attachments are top access techniques.

“Spearphishing attachments are a special type of phishing where the adversary uses attachments both to create an air of legitimacy — typically these attachments look like  professional invoices — and also to bypass security controls that don’t inspect attachments,” according to the report.

Staggeringly, 90% of phishing attachments are PDFs. Also, adversaries are most successful in convincing victims to download Trojans and other malicious files when they are delivered via cloud apps.

More than half of the malware that users have attempted to download so far this year was delivered via cloud apps. Users were lured into downloading malware from 477 distinct cloud apps, most notably Microsoft.

The report points out that the latter is not surprising, as Microsoft OneDrive is “the single most popular cloud app in the enterprise by a large margin.”

But not just spearphishing

Email, for its part, is still common, but has a low success rate. Enterprises have learned the hard way to employ sophisticated filters and users have been trained to spot fishy-looking imposters. However, personal email is a growing threat, Netskope reports, because it is commonly used on the same systems as business emails and can provide an avenue to access sensitive business data.

Adversaries also abuse popular social media apps and create SEO-optimized web pages around data voids and targeted to specific demographics. Similarly, calling and texting victims is an increasingly popular method (as was the case with MGM).

Finally, according to the report, once in a system, attackers are “heavily favoring” the use  of HTTP and HTTPS to “fly under the radar and blend in with benign traffic.”

Criminal adversaries tactical, diversified

Globally, Netskope customers were most commonly targeted by criminal adversaries — as opposed to geopolitical threat groups — based in Russia and Ukraine. Wizard Spider, the Russian group responsible for creating TrickBot malware, targeted more organizations than any other group.

“Most criminal adversaries have diversified their operations to use both ransomware and infostealers to increase the odds of a victim paying up,” the report reads, adding that the threatened public release of stolen sensitive information can be a good motivator for enterprises.

Many groups work transnationally and have an affiliate model that makes their operations even more dispersed, according to Netskope. These groups tend to develop playbooks optimized for targeting similar types of organizations so that they can “recycle tactics and techniques with minimal customization,” according to the report.

Meanwhile, the top geopolitical threat groups are based in China, and their most popular tools are remote access Trojans that create backdoors into organizations. Their most common targets are financial services and healthcare.

Anti-phishing defense that goes beyond email

As enterprises seek to bolster their defenses, Netskope researchers suggest the Mitre ATT&CK framework as a good source, as it provides a common language for adversary groups and their tactics. This can help enterprises determine whether their defenses are “appropriately matched” against their adversaries.

Organizations should also incorporate anti-phishing defenses that go beyond email, and provide additional protections against spearphishing, according to Netskope. An effective strategy should inspect all DNS, cloud and web traffic and HTTP and HTTPS downloads for evidence of phishing. These types of tools can incorporate threat intelligence, signatures, heuristics and AI.

High-risk file types (such as executables and archives) should be thoroughly inspected via a combination of static and dynamic analysis before they are downloaded, per Netskope research. Additionally, enterprises can detect and prevent adversary C2 traffic over web protocols using a secure web gateway (SWG). This can identify communication to known C2 infrastructure and common C2 patterns.

“An assessment of what traffic is inspected versus bypassed is vital for your defenses to protect users, data, applications and infrastructure from these adversaries,” the report emphasizes.

Furthermore, annually or biannually, enterprises should “assess how adversaries are pivoting to evade current defenses and review what new defenses are available.”