Tech News

Tech Business News

  • Home
  • Technology
  • Business
  • News
    • Technology News
    • Local Tech News
    • World Tech News
    • General News
    • News Stories
  • Media Releases
    • Tech Media Releases
    • General Media Releases
  • Advertisers
    • Advertiser Content
    • Promoted Content
    • Sponsored Whitepapers
    • Advertising Options
  • Cyber
  • Reports
  • People
  • Science
  • Articles
    • Opinion
    • Digital Marketing
    • Guest Publishers
  • About
    • Tech Business News
    • News Contributions -Submit
    • Journalist Application
    • Contact Us
Reading: Cybercriminals Add Three Novel Tactics To Phishing In Latest Attempts To Sneak Past Security
Share
Font ResizerAa
Tech Business NewsTech Business News
  • Home
  • Technology News
  • Business News
  • News Stories
  • General News
  • World News
  • Media Releases
Search
  • News
    • Technology News
    • Business News
    • Local News
    • News Stories
    • General News
    • World News
    • Global News
  • Media Releases
    • Tech Media Releases
    • General Press
  • Categories
    • Crypto News
    • Cyber
    • Digital Marketing
    • Education
    • Gadgets
    • Technology
    • Guest Publishers
    • IT Security
    • People In Technology
    • Reports
    • Science
    • Software
    • Stock Market
  • Promoted Content
    • Advertisers
    • Promoted
    • Sponsored Whitepapers
  • Contact & About
    • Contact Information
    • About Tech Business News
    • News Contributions & Submissions
Follow US
© 2022 Tech Business News- Australian Technology News. All Rights Reserved.
Tech Business News > Reports > Cybercriminals Add Three Novel Tactics To Phishing In Latest Attempts To Sneak Past Security
Reports

Cybercriminals Add Three Novel Tactics To Phishing In Latest Attempts To Sneak Past Security

The misuse of web translation, image-only emails, and the insertion of special characters

Austech Media
Last updated: March 22, 2023 2:33 pm
Austech Media
Share
SHARE

Cybercriminals are continuously evolving their phishing attacks, introducing new techniques and tactics in their attempts to trick victims, bypass security measures, and avoid detection.

A new Threat Spotlight from Barracuda Networks details three novel tactics that were detected in phishing attacks during January 2023. 

Barracuda researchers analyzed data of phishing emails blocked by Barracuda systems. And while the overall volume of attacks using these tactics is currently low – with each tactic making up less than 1% of attempted phishing attacks – they are widespread, with between 11% and 15% of organizations affected, often with multiple attacks. 

The three attack tactics detailed by Barracuda are:

  • Attacks using Google Translate web links.

In January, our researchers noted email attacks that used the Google Translate service for websites to hide malicious URLs (web page addresses). 

The tactic works like this: The attackers use poorly-formed HTML pages or a non-supported language to prevent Google from translating the webpage – and Google responds by providing a link back to the original URL stating that it cannot translate the underlying website.

The attackers embed that URL link in an email and if a recipient clicks on it, they are taken to a fake but authentic-looking website that is in fact a phishing website controlled by the attackers.

These attacks are difficult to detect since they contain a URL that points to a legitimate website. As a result, many email filtering technologies will allow these attacks through to users’ inboxes.

Further, the attackers can change the malicious payload at the time of email delivery, making them even harder to spot.  

Our data shows that just under one-in-eight (13%) of organizations were targeted with this type of phishing email in January 2023, each receiving on average around eight such emails during the month.

  • Image-based phishing attacks.

Image based attacks have been commonly used by spammers and Barracuda researchers have found that attackers are now increasingly using images, without any text, in their phishing attacks. These images, which can be fake forms such as invoices, include a link or a callback phone number that, when followed up, leads to phishing. Because these attacks do not include any text, traditional email security can struggle to detect them. 

Our data shows that around one-in-10 (11%) organizations were targeted with this type of phishing email in January 2023, each receiving on average around two such emails during the month.

Barracuda researchers believe that image-based phishing will be an increasingly popular tactic for cybercriminals in the future. 

  • The use of special characters in attacks

Hackers often use special characters, such as zero-width Unicode code points, punctuation, non-Latin script, or spaces, to evade detection. This type of tactic is also used in “typo-squatting” web address attacks, which mimic the genuine site but with a slight misspelling. When they are used in a phishing email, the special characters are not visible to the recipient.

The tactic can work like this: An attacker inserts a zero-width (no) space within the malicious URL embedded in a phishing email, breaking the URL pattern so that security technologies do not detect it as malicious.

Detection of such attacks can also be difficult because there are legitimate purposes for the use of special characters, such as within email signatures. 

Barracuda researchers found that in January 2023, more than one-in-seven (15%) organizations received phishing emails that use special characters in this way, each receiving on average around four such emails during the month. 

“Phishing is a common starting point for many cyberattacks, including ransomware, financial fraud and credential theft, and cybercriminals continue to develop their phishing approaches to trap unwary recipients and avoid being spotted and blocked,” said Olesia Klevchuk, product marketing director, Email Protection at Barracuda.

“To defend your organization, you need AI-enhanced email protection that can inspect the context, subject, sender, and more to determine whether a benign-looking email is in fact a well-disguised attack,”

“You also need to train your employees to understand, identify and report suspicious messages, plus tools that enable you to quickly identify and remove any traces of a malicious email from user inboxes and compromised accounts should a malicious email manage to break through.”

By Austech Media
Austech Media is Australian press release distribution and publishing organisation dedicated to the technology industry. Incorporating distribution of technology news and events
Previous Article Oracle Releases Java 20 Oracle Announces Release of Java 20 (Oracle JDK 20) 
Next Article Classhive Launches edutech Australia ClassHive Launches, Reducing Classroom Admin and Teacher Overwhelm
Leave a comment

Leave a Reply Cancel reply

You must be logged in to post a comment.

Cybercriminals Barracuda Networks phishing security

Tech Articles

Content creation platforms leveraged for phishing attacks

Phishing Attacks Exploit Content Creation Platforms

Content creation platforms are being leveraged for phishing attacks. Its…

September 17, 2024
Attitudes Toward Work Manifest The Rise of AI

Did Our Collective Attitudes Toward Work Manifest The Rise of Artificial Intelligence? (AI)

It’s definitely something to think about. There’s a fine line…

November 26, 2024
Nations Leading the Charge in Dead and Scam Crypto Projects

Top Nations Behind Scams And Dead Crypto Projects

An analysis of 1,500+ crypto ventures reveals the U.S. leading…

November 29, 2024

Recent News

231 Million Emails Emitting Over 70 Million Grams Of Carbon - Tech News
Reports

Over 231 Million Emails Were Sent Every Minute in 2022, Emitting 70 Million Grams Of Carbon

5 Min Read
SOTI - Michael Dyson, VP for Sales
Reports

SOTI Research Finds 93% of Aussies Embrace In-Store Tech, Yet 80% Worry About Data Security

7 Min Read
Social Media APAC 2024
Reports

The State of APAC’s Social Media in 2024: Trends and Insights

6 Min Read
Cyber Experts
CyberReports

KnowBe4’s Team of Cybersecurity Experts Release Predictions for 2022

6 Min Read
Tech News

Tech Business News

Stay up to date with the latest technology & business news trends from Australia and the around the world.

Technology News reports and whitepaper publishing services are available along with media and advertising options

Our Australian technology news includes People, Business, Science, World News, Local News, Guest publishers, IT News & Tech News Australia | Tech News was established in 2019

About

About Us 
Contact Us 
Privacy Policy
Copyright Policy
Terms & Conditions

December, 10, 2024

Contact

Contact Information.
Melbourne, Australia

Werribee 3030

Phone: +61 431401041

Hours : Monday to Friday, 9am 530-pm.


Tech News

© Copyright Tech Business News 

Latest Australian Tech News – 2024

Welcome Back!

Sign in to your account