HomeSecurityMobile phishing attacks: 161% increase against the energy sector

Mobile phishing attacks: 161% increase against the energy sector

Mobile phishing attacks targeting energy have increased by 161% compared to last year's figures (2nd half of 2020) and the trend shows no signs of slowing down.

mobile phishing

See also: DocuSign phishing campaign targets low-ranking employees

Although the risks of outdated and vulnerable devices plague all sectors, a new report from cybersecurity firm Lookout shows that the energy sector is the most targeted, followed by the finance, pharmaceutical, government and manufacturing sectors.

In terms of geographic targeting, Asia-Pacific tops the list, followed by Europe and then North America. However, there is a growing trend in phishing attacks targeting the global energy industry around the world.

And mobile phishing increased in the first half of 2021, with nearly 20% of all energy sector workers targeted in mobile phishing attacks, leading to a 161% increase compared to the previous six months.

With so many people working from home due to the COVID-19 pandemic, many employees are using VPNs to access corporate networks. Unfortunately, this remote access to a corporate network makes it an attractive target for threat actors, who use phishing to steal VPN or domain credentials.

See also: Google: APT28 phishing campaign targeted 14,000 Gmail users

In 67% of all phishing cases analyzed by Lookout researchers, threat actors perform credential theft. To conduct these campaigns, attackers use email, SMS, phishing apps, and login pages on fake corporate websites.

These credentials allow them to gain access to internal networks, which can then be used for further lateral movement and finding additional pivot points.

From there, they can identify vulnerable systems and launch attacks against industrial control systems that typically carry unknown vulnerabilities for years.

According to the report from Lookout, the most significant attack surface comes from the 56% of Android users running out-of-date and vulnerable versions of the operating system.

A full year after the release of Android 11, Lookout telemetry showed that only 44.1% of active Android devices were using it.

In contrast, iPhones are much less vulnerable to exploitation, as most iOS users are running the latest version.

Some of the flaws in older versions of Android are easily exploitable.

Mobile phishing attacks: 161% increase against the energy sector

See also: How phishing-as-a-service is a threat to organizations

Riskware is a bigger problem than malware

Apps that request dangerous permissions and access sensitive data on the device are now a bigger problem than “pure” malware, as they are much easier to pass through the app store's scrutiny.

Many of these applications connect to obscure servers and send various types of data that are unrelated to their core functionality, but still pose a great risk to the user and the organization that employs them.

Spyware, keyloggers, trojans, and even ransomware droppers are still a problem, but we are more likely to see them deployed in highly targeted attacks, so their distribution volumes are significantly smaller.

Therefore, employee training is critical to minimizing security gaps, as the human factor remains the biggest risk for malware installation.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS