Security Awareness Training Blog

Spear Phishing Blog

Learn about current spear phishing attacks, specific examples, and techniques the bad guys are currently using so your users don't fall for these attacks.

Russian Indictment: They Used Criminal Tradecraft like Spearphishing To Hack The Democratic Party

The email arrived in Hillary Clinton’s campaign chairman John Podesta’s inbox around March 19, 2016, during the height of the presidential primaries, spoofed to look like a standard ...
Continue Reading

State Department warns staff of surge in spear phishing attempts

Eric Geller at Politico reported: "The State Department on Thursday warned employees about a tidal wave of malicious messages attempting to trick staffers into opening a door for hackers. ...
Continue Reading

SAM.Gov Hackers Were Handed Spear Phishing, Spoofing & Credential Theft On A Gold Platter

Cybercrooks who stole federal payments by hacking contractor accounts on a GSA website used sophisticated spear phishing techniques to steal login credentials and then diverted payments ...
Continue Reading

An inventive YouTube moderator phishing scam

Full marks for inventiveness If you have a YouTube channel, and have had your fill of sifting through the vile torrent of abusive comments left on your video masterpieces, you can invite ...
Continue Reading

If Willie Sutton were working today, he'd be stealing cryptocurrency, not wasting time on banks

Because that's where the money is. Criminals have been installing cryptocurrency miners on victim machines that turn them into sources of money. These operate without the users' ...
Continue Reading

Surface Web vs. Deep Web vs. Dark Web: Differences Explained

These three terms are often a source of confusion, especially in connection with cybercrime and where that comes from. If you think that search engines like Google (there are more!) know ...
Continue Reading

Bad Rabbit Ransomware Attack Was Hiding A Spear Phishing Campaign

During the attacks in eastern Europe with the Bad Rabbit ransomware, a more insidious attack was taking place in Ukraine under its cover, Reuters reported. Serhiy Demedyuk, head of the ...
Continue Reading

U.S. warns about phishing attacks on nuclear, energy, aviation, water, and manufacturing industries

(Reuters) — The U.S government issued a rare public warning that sophisticated hackers are targeting energy and industrial firms, the latest sign that cyber attacks present an increasing ...
Continue Reading

Ransomware Spear Phishing Attack Used To Hide 60M Cyberheist

In a classic "divert their attention", the Taiwan Far East Bank was first attacked with spear phishing emails that pointed to malicious executables, which were clicked on by employees. ...
Continue Reading

A New Spear Phishing Attack Uses Compromised Government Servers And DNS

Cisco's Talos malware researchers posted about a highly sophisticated, targeted spear phishing attack using malicious Word attachments, spoofed to look like it was from the U.S. ...
Continue Reading

Third Quarter 2017 Top-Clicked Phishing Email Subjects [INFOGRAPHIC]

KnowBe4 customers run millions of phishing tests per year, and we report quarterly on the latest top-clicked phishing email subjects in 3 separate categories: subjects related to social ...
Continue Reading

A Phishing Attack in the Clouds May Rain On Your Parade

According to MeriTalk, an editorial and events organization that focuses on Federal IT and government computing technologies, governments are moving some, or all of their IT to the Cloud, ...
Continue Reading

New Defray Ransomware Demands $5,000 In Customized Spear Phishing Attacks

This newly discovered ransomware strain is targeting healthcare, education, manufacturing and tech sectors in the US and UK, using customized spear phishing emails. Defray is demanding a ...
Continue Reading

Ukrainian Coder May Be First Potential Witness of DNC Phishing Attack

A lengthy and fascinating article in the New York Times by Andrew E. Kramer and Andrew Higgens on August 16, 2017 reported that a Ukranian coder known to his friends on the “dark web” as ...
Continue Reading

This Is A First: Spear Phishing Attack Uses Compromised PowerPoint Slide Deck

Bad guys are exploiting the CVE-2017-0199 vulnerability to bypass endpoint security software and deliver the Remcos remote access Trojan via Microsoft PowerPoint decks. This particular ...
Continue Reading

APT28 Uses Spear Phishing and NSA EternalBlue Exploit To Attack Hotel Wi-Fi

Russian APT28 (aka the Fancy Bear hacking group) is harnessing EternalBlue; NSA's Windows SMB exploit which made the WannaCry ransomware and Petya so effective — and are using it to ...
Continue Reading

Top White House officials fall for prankster social engineering tricks

A UK-based email prankster used social engineering tactics to fool several top White House officials into responding to his messages, including the Trump administration’s cybersecurity ...
Continue Reading

Second Quarter 2017 Top-Clicked Phishing Email Subjects [INFOGRAPHIC]

KnowBe4 customers run millions of phishing tests per year, and we report at least quarterly on the latest top-clicked phishing email subjects so our customers know what the highest-risk ...
Continue Reading

Netflix, ABC Hacker Promises More Phishing: "Hollywood Is Under Attack"

The Hollywood Reporter (THR) talked directly to TheDarkOverlord hacking collective that claims to have studio films. They said: "We're in the business of earning vast amounts of internet ...
Continue Reading

Top Secret NSA Doc Shows Russians Spear-Phishing Election Officials

The Intercept reported that the GRU (Russian Military Intelligence, the FSB's counterpart) executed a cyberattack on at least one U.S. voting software supplier and sent spear-phishing ...
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews