VIPRE’s security team has released its annual report, “Email Security in 2024: An Expert Look at Email-Based Threats.” The study is based on the analysis of seven billion emails in 2023 and outlines what is expected to happen in the cyberattack landscape in 2024.

Of the seven billion emails analyzed, nearly one billion were found to be malicious. There was a worrying 276% increase in malware between January and December 2023. The research identified the Financial Services industry as the most frequently attacked by phishing and malspam emails, accounting for 22% of all attacks, with IT, Healthcare, Education and Government following closely behind. When it comes to phishing, 71% of emails still use links as the primary bait.
The research revealed that URLs from Microsoft, Apple, DHL, Google, DocuSign, Amazon, and Dropbox were among the most frequently spoofed. HTML attachments accounted for 52% of all malicious attachments, with PDFs up 100% and EMLs up an impressive 4600%. In the last quarter, AgentTesla — which was identified as a .NET information stealer — was responsible for the majority of malware attacks.
The report warned that 2024 will see an increase in QR code hacks or quishing, an increase in the use of artificial intelligence to generate content for spam emails, including deepfakes, a further increase in highly personalized social media mining; and widespread use of different file types and formats, particularly EML, to spread phishing and malware. A significant increase in state-sponsored attacks is also expected.
According to the findings, the popularity of clean links is increasing, as they have a higher success rate in deceiving users. In 2023, EML file attachments, despite being a constant threat, showed a tenfold increase in the fourth quarter. Due to their novelty, they often bypass basic email security measures and arouse curiosity in users, resulting in increased participation and risk.
AgentTesla, which emerged as the top malware family in Q4, infiltrates targets and harvests sensitive data from many high-quality browsers. Crucially, while malware delivery via email increased by 276% between January and December 2023, it was only responsible for 5% of total malspam. This suggests that it is easier for attackers to trick end users than security solutions, which, despite lagging behind emerging tactics such as social engineering attacks, have been able to effectively stop malware.
Information source: securitybrief.co.nz
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
