HomeSecurityAttacks that start with phishing emails are back in fashion

Attacks that start with phishing emails are back in fashion

Email attacks are back in fashion, with several new and well-known forms of ransomware being distributed using malicious payloads in phishing emails.

Email used to be the most prolific way to infect victims with ransomware, but in recent years, attackers have shifted their focus to other methods. Specifically, they are using remote ports, unpatched servers, or other vulnerabilities in corporate networks to infect and encrypt entire networks, demanding huge ransoms to give owners their data back.

phishing

However, in recent weeks, Proofpoint researchers have seen an increase in the number of ransomware attacks distributed via email – including one that hasn’t been active for years – with scammers sending hundreds of thousands of messages every day. The email attacks use a variety of enticements to trick people into opening them, including coronavirus-related topics.

One of the largest phishing campaigns is from a new ransomware called Avaddon. During one week in June, it was distributed in over a million messages, primarily targeting organizations in the US.

Avaddon it downloads Avaddon using PowerShell.

on infected computers demanding $800 in bitcoin in exchange for “special software” to decrypt the hard drive. The hackers warn that if users try to recover their files without payment, they will lose the files forever.

A second phishing email-based ransomware campaign, described in detail by researchers, was dubbed “Mr. Robot,” targeting construction companies in the U.S. The messages, which claim to be from the Department of Health, use topics related to COVID-19 test results in an attempt to trick victims into clicking a link to view a document.

If the victim clicks, this Philadelphia ransomware and the attackers demand $100 in exchange for the files. This is a very small amount compared to many ransomware campaigns, which suggests that it is targeting ordinary users and not businesses.

But it's not just organizations in North America that are increasingly being targeted by email ransomware attacks – the same is happening in Europe.

Researchers note that the Philadelphia ransomware – returning after a three-year hiatus – is targeting manufacturing and food companies in Germany with emails claiming to come from the German government.

The emails claim to contain information about the company's possible closure due to the COVID-19 pandemic, encouraging the victim to click on a link – if they do, Philadelphia ransomware is installed on the system, with a ransom note demanding $200 for decryption.

While the number of email-based ransomware attacks is still small compared to 2016 and 2017, when Locky, Cerber, and GlobeImposter were distributed in huge volumes of tens of millions, the recent increase in email attacks shows how agile cybercriminals are.

One reason why some attackers might return to phishing emails is because of the number of people now working remotely and the reliance on email that entails.

In many cases, it is possible to defend ourselves against ransomware by ensuring that networks are patched with the latest security updates, preventing attackers from exploiting known software flaws.

However, businesses should also always have a plan, as at some point someone will make the mistake of clicking on a malicious link in a phishing email.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS