Phishing Report: Current Trends

Cybersecurity banner

With rapidly generated and customized phishing attempts through the use of AI tools, details can quickly change, but some underlying trends continue to re-surface. Sharing awareness of these trends may help reduce the attack volume. Here are recent phishing techniques reported throughout the state along with suggested security controls:

Valid Account Compromise

The phishing attempts that spread are typically from a valid account. External valid senders may garner a small number of link clicks. Compromise of a valid account for the organization itself: many staff may click links and enter credentials. Be aware and prepared for phishing to continue to come from both external valid accounts and potentially the organization’s own accounts.

Common Trends

  • Google and Microsoft account compromise
  • Compromise without and with MFA in place
  • Account session token stealing, circumventing MFA without the user being prompted
  • Compromise of valid account followed by phishing of all that users’ contacts
  • Fake CAPTCHA web page as part of session token stealer process
  • Shared Google, Microsoft, Adobe, etc. documents with link in the document
  • Email messages or shared documents customized with recipient or sender organization’s logo, photos, signature line, etc.
  • ScreenConnect software installer
  • Newly registered domains used for links

Email Themes

The following types of emails have been prevalent recently:

  • Invitation
  • Job opportunities
  • Items for sale (example: sale of estate items)
  • Invoice with fake “reply chain” of email messages
  • Request for proposal
  • Transcript-related
  • HR-related (example: staff review)
  • New fax

Security Controls

The following controls may help reduce the scope and impact of phishing incidents:

  • Restrict users’ local admin rights to their computer.
  • Implement multi-factor authentication (even though MFA may not be phishing-resistant, it can still help).
  • Require passkeys for all critical software or administrator accounts; encourage everyone to use passkeys.
  • Block newly registered domains for the network (including guest wi-fi) via firewall, content and DNS filtering tools.
    • If devices go home with users, deploy content filter or DNS filter to these devices or user accounts.
  • Train staff to report any of the following:
    • link that leads to CAPTCHA prompt
    • link that leads to login prompt
    • email messages, PDF, Word, shared Google Drive or other document sharing that requires or has a primary goal of getting the user to click a link.
  • Stop, Think, Verify training for all staff. Staff should know that they need to verify with the sender via another means before providing credintials, downloading or installing anything or making a payment.
  • Report known malicious links which are not yet categorized as malcious to firewall vendor and filtering software vendor.
  • Contact other organizations to alert them if they have a compromised valid account.
  • Schedule phishing training scenarios, tailored to above types of email threats.

With phishing emails as an expanding threat vector, continued information sharing helps reduce the bredth of attacks. This article re-shares intelligence shared through assorted channels. Please continue information sharing in the communitiy and with MOREnet. This blog article will be updated regularly, as more trends emerge.

Related Articles

Security Alert: “Invitation” Phishing Attempt

Back to School Cybersecurity Training: Four Simple Habits to Keep Your Organization Safe

Vishing and Phishing – Threat Actor Techniques