New Evasive Phishing Techniques Help Cybercriminals Launch “Untraceable” Campaigns

Stu Sjouwerman | Jun 29, 2022

New Evasive Phishing TechniqueScary new details emerge of cybercriminals using reverse tunneling and URL shorteners to evade detection by security solutions, allowing them to take victims for their credentials and more.

We expect that as threat actors change their techniques, security solutions will keep up and detect attacks as they occur and before they can do any damage. But a new report from security vendor CloudSEK highlights a new campaign that allows the threat actors to host malicious webpages on their own local computers using a mix of reverse tunneling technology and URL shorteners.

According to the report, the use of reverse tunnel services allows threat actors to generate random URLs that avoid detection as being malicious, further obfuscating the URLs by running them through URL shorteners like Bit.ly, is.gd, and cutt.ly.

While these techniques aren’t necessarily new, the report does note that there is an increase in frequency and sophistication to these attacks, making them far more likely to be successful.

But in the end, the real success behind these phishing attacks – even those that use these advanced evasion techniques – is whether the recipient falls for the social engineering found in the email content and the malicious landing page hosted by the threat actor.

Users that are continually kept updated with Security Awareness Training are far more likely to see these scams for what they really are and far less likely to fall victim to such attacks.

This report makes it clear that threat actors are working to find ingenious ways to keep security solutions from detecting an attack, making it more imperative for organizations to empower users through continual training to play a role in stopping attacks.

Topics: Phishing

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.