Thursday, 6 November 2025
33.5 C
Singapore
27.3 C
Thailand
25.8 C
Indonesia
29.2 C
Philippines

Hackers exploit Russian domains for phishing attacks

Hackers are bypassing email security by exploiting Russian domains and advanced phishing tactics, including RATs and malicious Office documents.

Recent research has revealed a concerning rise in phishing attacks as hackers adapt their methods to bypass advanced email security systems. The latest data shows a significant increase in the volume and complexity of malicious emails, evading Secure Email Gateways (SEGs) like Microsoft and Proofpoint. These findings come from Cofense Intelligence’s third-quarter Trends Report, highlighting a notable surge in cyber threats.

At least one malicious email slips through SEGs every 45 seconds, an alarming increase from last year’s rate of one every 57 seconds. This trend underscores the growing sophistication of phishing campaigns targeting unsuspecting users and organisations.

Remote Access Trojans (RATs) on the rise

One of the key findings in the report is the sharp increase in Remote Access Trojan (RAT) usage. RATs are a powerful tool for cybercriminals, enabling them to take control of victims’ systems remotely. Once inside, attackers can steal sensitive data, install additional malware, and maintain persistent access to compromised networks.

A significant player in this rise is the Remcos RAT, a widely used tool that grants attackers complete control over infected devices. With the ability to exfiltrate data and deploy further exploits, Remcos RAT is a favourite among hackers.

Additionally, open redirects have become a popular technique in phishing campaigns, with a staggering 627% increase in their use. Open redirects exploit legitimate websites by redirecting users to malicious URLs, often disguised behind trusted domains. Popular platforms like TikTok and Google AMP are frequently abused in such attacks due to their high traffic and widespread user base.

Malicious Office documents and phishing

The report also highlights a dramatic 600% rise in the use of malicious Microsoft Office documents, particularly those in the .docx format. These files often include phishing links or QR codes that expose victims to harmful websites.

Microsoft Office documents remain a preferred attack vector for cybercriminals due to their prevalent use in professional settings. Spear-phishing campaigns exploit these documents to target businesses, demonstrating the attackers’ strategic focus.

Shift towards Russian domains

Hackers are also turning to less common domain extensions like .ru (Russia) and .su (Soviet Union) for data exfiltration. These top-level domains (TLDs) have seen usage spikes of over fourfold and twelvefold, respectively. Using such domains allows cybercriminals to evade detection, making it harder for victims and security teams to trace stolen data.

These findings suggest a clear shift in attack tactics as cybercriminals refine their methods to stay ahead of security measures. With phishing attacks becoming more complex, organisations must remain vigilant, update their security protocols, and educate users about the evolving threats.

Hot this week

Tenity concludes SingHacks 2025, Asia’s first fintech-focused agentic AI hackathon

Tenity concludes SingHacks 2025, Asia’s first fintech-focused agentic AI hackathon, ahead of its grand finals at Singapore FinTech Festival.

Double-day sales drive growth across Southeast Asia in Q4 2024

Criteo reports strong Q4 growth in Southeast Asia as double-day sales like 11.11 drive new buyers, higher spending, and regional retail gains.

ECOVACS turns up the 11.11 excitement with unbeatable deals on its smart cleaning robots

ECOVACS celebrates 11.11 with up to 76% off its top cleaning robots, free gifts for early buyers, and a chance to win an iPhone 17 Pro.

Nokia strengthens partnership with SoftBank to modernise Japan’s 4G and 5G networks

Nokia expands partnership with SoftBank to modernise Japan’s 4G and 5G networks using AI-powered AirScale and MantaRay solutions.

Coolmate secures Series C funding to accelerate expansion and global ambitions

Coolmate secures Series C funding led by Vertex Growth Fund to drive women’s wear, global expansion, and offline retail growth.

WhatsApp launches new app for Apple Watch

WhatsApp introduces its new Apple Watch app, bringing voice messages, reactions, media viewing, and full chat access to the wrist.

Armis secures US$435 million in pre-IPO funding at US$6.1 billion valuation

Armis raises US$435 million in a pre-IPO round led by Goldman Sachs, valuing the cybersecurity firm at US$6.1 billion.

Thoughtworks’ latest Technology Radar explores AI’s rapid evolution in enterprise development

Thoughtworks’ Technology Radar 33 reveals how AI assistance, agentic systems, and new protocols are reshaping enterprise software.

Google Pixel Watch 4 review: AI-powered insights meet a brilliant new display

Google Pixel Watch 4 combines a brighter display, smarter AI, and deeper health insights in a refined, premium smartwatch.

Related Articles

Popular Categories