This blog is released in partnership with Mobile Ecosystem Forum (MEF), of which WMC Global is a proud member.
WMC Global Threat Intelligence Team
Recent posts by WMC Global Threat Intelligence Team
6 min read
Phishing Lures Imitate Government Bodies Offering COVID-19 Relief
By WMC Global Threat Intelligence Team on 8/11/21 8:31 AM
Topics: Covid Phishing Covid-19 Phishing Kit Threat Intel Government US Government UK Government NHS
2 min read
Phishing for Finance - Akamai x WMC Global SOTI Report
By WMC Global Threat Intelligence Team on 5/19/21 3:00 PM
Cloud and enterprise security leader Akamai has partnered with WMC Global researchers to release their State of the Internet report focusing on phishing in the financial services industry. We have included key excerpts below and access the full report HERE.
HIGHLIGHTS
- In 2020, there were 193 billion credential stuffing attacks globally, with 3.4 billion of them in the financial services space, representing a 45% growth over 2019.
- The number of web attacks targeting the financial services industry grew by 62%. Akamai observed 736,071,428 web attacks recorded against financial services in 2020. What was the number one web attack type targeting financial services? Local File Inclusion (52%), followed by SQL Injection (33%) and Cross-Site Scripting (9%).
- The Kr3pto phishing kit, which targets financial institutions and their customers via SMS, has been observed spoofing 11 brands across more than 8,000 domains since May 2020. Akamai and WMC Global has tracked Kr3pto campaigns across more than 80 different hosts (ASNs), including one host that housed more than 6,000 Kr3pto domains.
- An API used by the Ex-Robotos phishing kit, which targets corporate credentials, logged more than 220,000 hits over 43 days, with peaks in the first week of February 2021 reaching tens of thousands per day.
FINANCIAL PHISHING
Over the past several years, phishing has remained a constant variable in many of the data breaches and security incidents that have dominated the headlines. Criminals have dedicated a good deal of energy and resources toward advancing the phishing economy on a regular basis. Gone are the days of basic cloned websites. Today, phishing is a turnkey business, even offered as a hosted solution for criminals who wish to leverage phishing-as-a-service developments.
As phishing attacks and kit development started to advance, defenders realized that usernames and passwords alone were not enough. To combat the phishing onslaught and other password-based attacks, defenders turned toward multi-factor authentication (MFA) and two-factor authentication (2FA) to help augment basic passwords. While 2FA is a subset of MFA, both provide the means of a second type of authentication, such as a PIN or one- time password (OTP). Often, 2FA is associated with SMS-based OTPs, whereas MFA is associated with authenticators, like Google Authenticator.
Fast-forward to today — the criminals have evolved. This change includes elements that target 2FA and MFA protections, where victims are tricked into filling out their OTP or revealing it to the threat actor during a conversation.
In this report, WMC Global and Akamai present research related to threat actors and the phishing kits being used to target the financial services industry, or people within it. One relatively new threat actor poses a serious threat to the financial services industry in the UK, with the development of dynamic phishing kits that effectively bypass secondary methods of authentication.
Topics: Phishing finance Banking
4 min read
Hermes SMS Courier Scam
By WMC Global Threat Intelligence Team on 4/27/21 1:05 PM
Threat Summary
New phishing campaigns are targeting mobile devices to deliver fraudulent courier delivery notifications to potential victims. While many organizations secure email and Microsoft Office applications directly within mobile phones, SMS threats are typically out of scope for many security teams, letting attackers exploit the lapse in coverage to leverage both consumer and business credentials. WMC Global's Threat Intelligence Team is currently tracking an increase in SMS-based courier scams in the United Kingdom. By the end of March over 5000 phishing URLs had been collected targeting Hermes alone. Targeted couriers are Hermes, DPD, and Royal Mail, with Hermes seeing a notable increase in distribution.
Topics: SMS Attack Phishing Hermes Courier Scam
16 min read
The Compact Campaign
By WMC Global Threat Intelligence Team on 3/4/21 12:27 PM
SuMMARY
Phishing campaigns continue to utilize the disruption of the pandemic to target victims, and a new campaign takes advantage of Zoom's rising popularity. Since December, the "Compact" Campaign has been targeting thousands of users by impersonating a Zoom invite and is estimated to have collected over 400,000 Outlook Web Access and Office 365 credentials. This campaign is unique in its use of trusted domains to ensure delivery of phishing emails and preventing phishing pages from being blocked. This is especially worrisome for organizations who will struggle to defend against this attack.
Topics: Phishing Phishing Kit Data Exfiltration Microsoft Office 365 Zoom
24 min read
Year-End Phishing Report - 2020 WMC GLOBAL
By WMC Global Threat Intelligence Team on 2/19/21 10:15 AM
Summary
WMC Global's Threat Intel Team analyzed thousands of phishing kits in 2020. While "16Shop" continues to be the most popular, kits capable of capturing gathering multi-factor authentication data, like "Puppeteer," are emerging. There was a large increase in SMS phishing compared to emails over 2020, indicating SMS will continue to be a substantial threat in 2021. WMC Global observed that consumer brands continued to be the primary target for phishing, with Netflix and Facebook being the most impersonated brands; however, WMC Global also observed new threat vectors for phishing in the form of COVID-themed phishing. The United States was the number one location for hosting phishing sites, with NameCheap being the provider hosting the most phishing sites over 2020. WMC Global predicts that in 2021 multi-factor authentication will become a focus for threat actors, phishing link delivery methods will continue to evolve, and phishing kit intelligence will be more prevalent in tracking threat actors.
Topics: SMS Attack Phishing Kit finance Netflix Puppeteer Kit
11 min read
Evolution of a Phish: Popular UPS Email Scam Now Targets Mobile Users
By WMC Global Threat Intelligence Team on 2/17/21 9:03 AM
Phishers are well known for identifying and exploiting security weaknesses. Many email and security teams are becoming more effective at blocking attacks, but phishers are targeting new gaps in remote workforce and SMS phishing detection. Specifically, threat actors are increasing the delivery of phishing campaigns via text message to avoid email vendor protections to deliver phishing directly to victims.
Topics: SMS Attack Phishing Phishing Kit Courier Scam UPS
2 min read
Threat Actor Update: Kr3pto
By WMC Global Threat Intelligence Team on 2/3/21 2:12 PM
The current biggest threat to the UK banking industry has just added a new target.
Topics: Phishing Phishing Kit Bank of Scotland Kr3pto
6 min read
Kr3pto Puppeteer Kits: Dynamic Phishing Kit Targeting UK Banking Customers
By WMC Global Threat Intelligence Team on 12/16/20 10:00 AM
At WMC Global, we are tracking a threat actor who goes by the alias "Kr3pto," a phishing kit developer who builds and sells unique kits targeting UK financial institutions amongst other brands.
Topics: Phishing Kit finance Kr3pto Banking Puppeteer Kit Multi-Factor Authentication
6 min read
Phishing Exfiltration Method: Email
By WMC Global Threat Intelligence Team on 11/13/20 10:06 AM
Phishing attacks have been on the rise in recent years, and 2020 in particular has seen a stark increase in phishing incidents since the start of the pandemic in January[i]. Tech companies and banks are the most commonly impersonated companies in phishing scams, which steal their victims credentials and other sensitive data and send them to the scammer[ii].