A New Attack Category is Born: You Now Need to Also Worry About Evasive Spear Phishing

Stu Sjouwerman | Oct 16, 2019
AdobeStock_58438858Researchers have combed through 25 million emails and found a new method of attack that blends two previously seen attack types combined into a single attack.
 
A cybercriminal needs to overcome two basic hurdles to infect a machine: First, they need get past any security solutions that inspect attachments looking for signs of maliciousness. Second, they need to get users to click on said attachment. If you can do both of these things, you have yourself a pretty good chance of infection. 
 
Thus far, we’ve only seen attacks that do one or the other well, or use two completely separate tactics to accomplish this. But, according to research from security vendors Glasswall and Forcepoint, a new attack method effectively combines these two tactics into a single attack. Dubbed evasive spear phishing, involves both very targeted spear phishing campaigns using contextual details that indicate a fair amount of diligence and sophisticated malware delivery mechanisms that leverage older Office filetypes.
 
According to the research, nearly half of all attacks are targeting Technology firms, with developers as the potential victim, likely looking for intellectual property. For each industry, there is a victim demographic, demonstrating that these attacks are not opportunistic, but are laser focused on trying to access and steal very specific kinds of information.

Organizations need to empower users to act as the last line of defense against evasive attacks designed to keep from being detected by security solutions.

Security Awareness Training educates users on how to spot suspicious emails – even when they are designed to look contextually accurate for the target victim.

A new category of attack should be a warning that the bad guys are stepping up their game and are working to leverage the weakest (and last) link in the chain – your users. Take note and be ready.

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.