{"id":28289,"date":"2017-03-28T19:28:52","date_gmt":"2017-03-28T11:28:52","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=28289"},"modified":"2017-03-29T10:01:28","modified_gmt":"2017-03-29T02:01:28","slug":"menlo-security-uncovers-new-spear-phishing-campaign-leveraging-multiple-scripts-to-customize-attacks-on-enterprises","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2017\/03\/28\/menlo-security-uncovers-new-spear-phishing-campaign-leveraging-multiple-scripts-to-customize-attacks-on-enterprises\/","title":{"rendered":"Spear phishing operation uses multiple scripts to customize attacks on firms"},"content":{"rendered":"<p><strong>Menlo Security, a player in cloud-based isolation security technology, announced that its cybersecurity researchers recently uncovered a new spear phishing attack at a well-known enterprise that went undetected by existing security solutions.<\/strong><\/p>\n<p><a href=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/03\/Menlo.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-28290\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/03\/Menlo.jpg\" alt=\"\" width=\"620\" height=\"445\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/03\/Menlo.jpg 620w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/03\/Menlo-300x215.jpg 300w\" sizes=\"auto, (max-width: 620px) 100vw, 620px\" \/><\/a><\/p>\n<p>A close examination of the recent spear phishing event by Menlo Security researchers revealed the following details:<\/p>\n<ul>\n<li>The attackers performed various checks on the password entered by the victim and their IP address to determine whether it was a true compromise versus somebody who had figured out the attack.<\/li>\n<li>The attackers supported various email providers. This was determined by the fact that they served custom pages based on the email domain. For example, a victim whose email address was john.doe@gmail.com would be served a page that looked like a Gmail login page.<\/li>\n<li>The attackers exfiltrated the victim\u2019s personally identifiable information (PII) to an attacker controlled account.<\/li>\n<li>The attacker relied heavily on several key scripts to execute the phishing campaign, and to obtain the victim\u2019s IP address in addition to the victim\u2019s country and city.<\/li>\n<\/ul>\n<p>\u201cCredential theft via increasingly sophisticated spear phishing attacks is dangerous to the enterprise,\u201d said Poornima DeBolle, chief product officer and co-founder of Menlo Security. \u201cExisting email security products will have a difficult time detecting these attacks using the usual good versus bad methods. Once an attacker obtains an employee\u2019s credentials, they have the keys to your kingdom.\u201d<\/p>\n<p>The spear phishing vulnerabilities stem from legacy email security solutions, including sandbox-based anti-phishing products, being largely based on reputation; that is, whether an email link is known to be \u201cgood\u201d or \u201cbad.\u201d A link\u2019s reputation is determined via third-party data feeds, or internally by way of large-scale email traffic and data analysis.<\/p>\n<p>In the case of spear phishing attacks, which target specific individuals within an organization, the email link is usually unique, as is the target user, hence there is no third-party reputation data available, nor is there enough data to analyze internally to make an accurate determination. If the determination is incorrect, users are sent directly to a web site where credentials can be stolen or malware can be downloaded to the user\u2019s device.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Menlo Security, a player in cloud-based isolation security technology, announced that its cybersecurity researchers recently uncovered a new spear phishing attack at a well-known enterprise that went undetected by existing security solutions.<\/p>\n","protected":false},"author":6,"featured_media":28290,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[4380,657,54],"class_list":["post-28289","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-menlo-security","tag-phishing","tag-security"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/28289","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=28289"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/28289\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/28290"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=28289"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=28289"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=28289"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}