According to a VIPRE report, 85% of phishing emails used malicious links in the email content, while spam emails increased by 30% from the first quarter to the second quarter of 2023.
Information technology organizations surpassed financial institutions (9%) as the most targeted sector for phishing in the second quarter compared to VIPRE's previous quarterly report.
See also: Ransomware is one of the top three threats to the survival of orgs

New macro-less malspam email campaign
- 58% of malicious emails used fake content
- 67% of spam emails in the second quarter came from the US
- Qakbot was the top malware family in Q2 2023
During its analysis, VIPRE also discovered a new macro-less malspam email campaign, containing a forged “.docx” file. This particular campaign contained a malicious external resource page that is called when the victim opens the.
A previously unknown malspam email campaign exploits the CVE-2022-30190 (or “Follina”) vulnerability, facilitating remote code execution (RCE) on the victim’s system by exploiting the Microsoft Support Diagnostic Tool (MSDT).
Additionally, in Q2 2023, 58% (~130 million) of the nearly 230 million malicious emails VIPRE detected used malicious content. Similarly, 42% (~95.7 million) of these emails involved malicious links, and most interestingly, VIPRE detected 90,000 of the 5 million malicious attachments with behavioral tracking.
See also: Anonymous Sudan: They hacked X to pressure Elon Musk
Malicious content
Malicious content is likely to top the list for Q2 2023, as security awareness programs become more common, making users less likely to open suspicious links or attachments. Cybercriminals use malicious content to trick victims into taking an action, such as authorizing or submitting a payment – which is much harder to detect.
The effectiveness of malicious content also explains why such a large percentage of scam emails (48%) in the second quarter were BEC scams, as they typically favor content over links or attachments.
According to the report, the top targets of email attacks shifted significantly from Q1 to Q2 2023, with financial institutions dropping dramatically from 25% in Q1 to just 9% in Q2. This decline is likely due to the fact that financial institutions continue to invest resources in preventing these attacks, resulting in a decrease in the success rate of cybercriminals.
See also: Hackers hold healthcare providers hostage

QR codes as a phishing attack vector
During the assessment, VIPRE also discovered that many phishing email identifiers used QR codes as their primary attack method, which redirected users to a phishing page. The increased use of QR codes suggests that users are increasingly aware of traditional email attack techniques, such as malicious links or attachments, forcing hackers to opt for more unconventional methods.
Although the majority (67%) of spam emails originate from the United States, cybercriminals hide their location of origin to avoid detection.
Information source: helpnetsecurity.com
