Friday, 31 January 2025
24 C
Singapore
20.4 C
Thailand
20.2 C
Indonesia
25.9 C
Philippines

Hackers exploit Russian domains for phishing attacks

Hackers are bypassing email security by exploiting Russian domains and advanced phishing tactics, including RATs and malicious Office documents.

Recent research has revealed a concerning rise in phishing attacks as hackers adapt their methods to bypass advanced email security systems. The latest data shows a significant increase in the volume and complexity of malicious emails, evading Secure Email Gateways (SEGs) like Microsoft and Proofpoint. These findings come from Cofense Intelligenceโ€™s third-quarter Trends Report, highlighting a notable surge in cyber threats.

At least one malicious email slips through SEGs every 45 seconds, an alarming increase from last yearโ€™s rate of one every 57 seconds. This trend underscores the growing sophistication of phishing campaigns targeting unsuspecting users and organisations.

Remote Access Trojans (RATs) on the rise

One of the key findings in the report is the sharp increase in Remote Access Trojan (RAT) usage. RATs are a powerful tool for cybercriminals, enabling them to take control of victimsโ€™ systems remotely. Once inside, attackers can steal sensitive data, install additional malware, and maintain persistent access to compromised networks.

A significant player in this rise is the Remcos RAT, a widely used tool that grants attackers complete control over infected devices. With the ability to exfiltrate data and deploy further exploits, Remcos RAT is a favourite among hackers.

Additionally, open redirects have become a popular technique in phishing campaigns, with a staggering 627% increase in their use. Open redirects exploit legitimate websites by redirecting users to malicious URLs, often disguised behind trusted domains. Popular platforms like TikTok and Google AMP are frequently abused in such attacks due to their high traffic and widespread user base.

Malicious Office documents and phishing

The report also highlights a dramatic 600% rise in the use of malicious Microsoft Office documents, particularly those in the .docx format. These files often include phishing links or QR codes that expose victims to harmful websites.

Microsoft Office documents remain a preferred attack vector for cybercriminals due to their prevalent use in professional settings. Spear-phishing campaigns exploit these documents to target businesses, demonstrating the attackers’ strategic focus.

Shift towards Russian domains

Hackers are also turning to less common domain extensions like .ru (Russia) and .su (Soviet Union) for data exfiltration. These top-level domains (TLDs) have seen usage spikes of over fourfold and twelvefold, respectively. Using such domains allows cybercriminals to evade detection, making it harder for victims and security teams to trace stolen data.

These findings suggest a clear shift in attack tactics as cybercriminals refine their methods to stay ahead of security measures. With phishing attacks becoming more complex, organisations must remain vigilant, update their security protocols, and educate users about the evolving threats.

Hot this week

Bytedance explores alternatives to selling TikTokโ€™s US operations

Bytedance explores non-sale options for TikTok's US operations as US-China talks continue, aiming to address national security concerns and maintain users.

OPPO claims Find N5 is thinner than Appleโ€™s iPad Pro (M4)

OPPO is teasing its Find N5 foldable phone, claiming itโ€™s thinner than Appleโ€™s iPad Pro (M4). It is expected to launch globally in February 2025.

TikTok remains unavailable in the App Store

TikTok remains unavailable for download in the App Store, so users in the US cannot install or update the app.

DeepSeek overtakes ChatGPT as the No. 1 app on the App Store

DeepSeek surges past ChatGPT as the No. 1 app, revolutionising AI with efficient training methods and global appeal while facing challenges.

Preorders open for SuperStation One, a modern twist on the PS One

Retro Remake is opening preorders for the SuperStation One, a US$179.99 PS One FPGA clone with wide retro gaming support. It ships in Q4 or earlier.

Microsoftโ€™s AI business thrives while Xbox struggles

Microsoftโ€™s AI and cloud business is booming, but Xbox is struggling. Gaming revenue fell 7%, while AI growth surged 175% year-over-year.

Meta remains confident despite DeepSeekโ€™s advancements

Mark Zuckerberg reassures investors that DeepSeekโ€™s AI rise does not threaten Meta, as the company reports strong Q4 results and AI investment plans.

Meta agrees to US$25 million settlement over Trump account suspension lawsuit

Meta has agreed to pay US$25 million to settle Trumpโ€™s lawsuit over his account suspension, with most funds going to his presidential library.

Comcastโ€™s new โ€˜ultra-low lagโ€™ technology aims to transform internet speed

Comcast is rolling out ultra-low lag internet technology to improve video calls and gaming. Major cities will see upgrades, cutting latency by 78%.

Related Articles