Maria Korolov
Contributing writer

How to stay one step ahead of phishing attacks

How-To
Dec 2, 201312 mins

Phishers are upping their game, so end users need to respond accordingly

Protecting yourself against phishing attacks used to be relatively easy. Don’t download unexpected attachments. Visit banking websites directly instead of clicking on links in an email. And look for bad grammar.

Those days are gone. Today, a phishing attack can come from any direction via any channel.

Consider the case of “Anna,” an employee of a bank’s treasury department. She was expecting a baby and was in the process of decorating a nursery. She got an email from the producers of a design show who wanted to talk to her in person about her preparation for the baby, and the challenge of being a working woman. The interview went well … but not for her.

“We were actually able to go in and conduct the interview, and get access to her computer system, and compromise the treasury accounts,” says J.J. Thompson. “And we got her to click on the link we wanted her to click on, which we used to download a payload to her computer,” he adds.

Luckily for Anna and her bank, this was a test, rather than a real attack. But the reason it worked is that Rook Consulting, the IT security consulting firm that Thompson heads, did its homework. First, they got a list of the employees at the company. These lists are available from list brokers, or from LinkedIn.

Next, they ran them through search engines and social networking sites. “Anna,” for example, discussed her baby preparations on Facebook and on Houzz, a decorating-themed social site. Finally, they contacted “Anna” by posing as Houzz. Since she already knew and trusted that company, she was ready to listen.

The lessons here? If it’s too good to be true, it probably is. And, like the old Cold War saying goes, “trust but verify.”

“If something seems like it happened out of the blue, and it’s something you would like, you should find a way to check the authenticity of that person,” says Thompson. “Look up Houzz’ number – don’t trust the number they provided to you.”

Another easy channel into a company is to make a job offer the target can’t refuse. “The exact great job, sent to the exact right person, from someone who seems legitimate and communicates frequently – and they have a link to malware that compromises the system,” says Thompson.

And we got her to click on the link we wanted her to click on, which we used to download a payload to her computer.

— J.J. Thompson of Rook Consulting

He adds. “People want to be accessible, they want to make themselves available to people from high school they haven’t seen for 15 years. People want to be open to new job opportunities. It is really scary.”

What’s the rush?

A senior partner at a law firm Thompson works with was on his way to court. His corporate email was down, and he needed the case file sent immediately to his personal email account so that he could prep. Or so he said in an email sent from that personal Gmail account.

Sounds legitimate, especially if you know that the attorney was, in fact, scheduled to be in court that day.

But the email was faked. The case was high-profile and important enough that somebody out there cared enough to spend the time it took to do their research, so they could target just the right person, at just the right time. And it looked completely legitimate.

“That staffer didn’t hesitate,” says Thompson. “They grabbed the case and sent it right off to that Gmail account.”

The tip off in this particular case should have been the urgency involved. “If something is rushed or urgent, verify outside the channel,” he says. “Pick up the phone and call them.”

This wasn’t a unique case, says Thompson. In fact, it’s happening more and more often to service companies of all sizes.

“If you’re a defense contractor and you’ve done a good job securing your systems, your providers – like ad agencies or law firms – may not have invested as much in security as you have,” he says. “So a lot of these service provider firms are starting to be attacked.”

Urgent emails can take many forms. One common tactic is to send out an email that sounds very familiar – maybe because the employee routinely receives many such emails – that has a deadline.

“Take, for example, compliance,” says Tom Keigher, senior penetration tester and security researcher at Foreground Security, in Lake Mary, Fla. “The email says, ‘We have regulatory obligations and we need you to participate by this date.’ So they’re going to hurry up and get it done. They’re worried about time management, not worrying about whether it’s a real email.”

Another example is an email that supposedly comes from the HR department, and promises iPads or spaces in the corporate garage to the first 10 respondents.

Or one that comes from a conference coming up soon in your industry and offers a personal Q&A with the featured speaker – details in the attachment.

Even mass-mail phishing letters are getting more professional. There are now complete phishing kits available, says Jeff McGurk, manager of incident response group at Lindon, Utah-based AccessData Group, a forensic software vendor. The bad guys can get a ready-to-go phishing package with emails realistic enough to get past the filters, written in perfect and fluent English.

Then, instead of setting up one fake site, they’ll use a hacked shared web server, where they can get access to a hundred legitimate websites at once.

The bad guys are still trying to get people to go to a look-alike site to enter their personal banking login and password. But these days, many are aiming higher. Instead of one user name and password, they’ll get all of them by scanning your browser for vulnerabilities and installing spyware – in the time it takes you to decide that there’s nothing on the site worth seeing and closing the window.

You don’t even have to download anything. And while you can keep your browser patched and up-to-date, that won’t protect you against zero-day vulnerabilities.

And who wouldn’t click on a link, especially if it’s on a topic of interest to you, and seems to come from a trusted friend or colleague?

“One technique I like is the technique where you preface the email with a phone call,” says Keigher. “I would call you up and say, ‘I’m so-and-so, and I would like your input on something, can I send you something by email?’ Now you’re expecting this email, and would be more likely to click a link.”

If the link arrived via text message or email that you’re reading on your cell phone, you might not have the time to double-check it before clicking.

“It doesn’t have the same degree of attention,” says Jerry Irvine, CIO of Prescient Solutions, a Shaumberg, Ill., technology outsourcing firm. “I’m half looking at the device, and half looking at the road, or talking to someone. It’s a significantly more successful means of phishing.”

In fact, mobile devices may be the primary target.

“They haven’t eliminated targeting workstations,” says Irvine. “But because of the inefficiencies and insecurities of mobile devices, mobile devices are the Wild West of the IT world right now. There are few anti-virus solutions for mobile devices. In fact, many anti-virus solutions you can download are actually viruses themselves.”

Android devices are particularly vulnerable here because there is no central company to push out patches and updates to plug security holes, users can download and install any software they want, and apps have the power to cause more damage.

According to a July report by Kindsight Security Labs, one out of every 100 Android phones is already infected. In May of this year, Android became the most popular mobile platform for infections, with tethered Windows laptops falling from more than 65 percent of all mobile infections at the start of the year, to less than 45 percent in June. Infections on iPhones, Blackberries, and other devices accounted for less than 1 percent of all mobile infections, the company said.

But Irvine warned that no platform is completely safe. “Nobody should say, ‘I have an Apple phone, I can’t be hacked.’”

Another common activity that used to be considered safe was opening PDF attachments. Research reports, white papers, press releases, slide decks, memos – they all come in the familiar, secure, PDF packaging.

Or, they used to. Now, even a PDF file can be carrying a malicious payload, such as an email from a trusted source in which the PDF is supposed to contain customer requirements.

For example, an email may come in from someone claiming to be interested in buying telecom services, says Golan Ben-Oni, a CISO at a US-based telecom company. “We do see some frequency of those,” he says. “It can be problematic.”

One solution to the PDF problem, as well as to other document types that may be carrying a dangerous payload, is to convert the document to another format before opening it.

“With one of our cloud providers, we have the option to take that document and just extract the relevant text out of it,” he says.

Instead of seeing the attached document, the user sees a link to the converted file.

“You’re removing the teeth of the weaponized part of the document,” says Ben-Oni.

If a dangerous payload does get through, or a machine starts acting in an usual way that might indicate that it’s been compromised, it’s immediately removed from the network, forensically imaged, re-imaged from a trusted master, then released back to the user.

Ben-Oni says the company tries to start this process within minutes of when the problem is discovered.

Another recommendation is not to allow lateral communications – local area networks typically allow free and open communication between computers. “There’s absolutely no reason why one machine like a laptop or desktop sitting on a network should have any reason at all to communicate with another machine on the network directly,” he says.

Immediate payout

Most phishing attacks are designed to allow a hacker to infiltrate a company’s systems and gather as much information as they can. The goal is to avoid discovery as long as possible.

But there’s a new game in town, says Ryan Laus, network manager at Central Michigan University. It’s called “ransomware.”

“In a nutshell, a user receives a phishing email that fools the user into opening a file,” says Laus. “The attached file contains a specialized piece of malware that will encrypt the contents of a user’s hard drive, including mapped and shared devices.”

To get the data back, the user has to pay a ransom by a certain date. Worst of all, in many cases the bad guys take the money and run, without ever handing over the decryption keys.

“The data can no longer be recovered unless the user has a ‘cold’ backup of the data that the malware has not been able to access,” Laus says.

Another ransomware tactic is to fill your computer screen with child pornography – followed by a message, supposedly from a government agency, telling you that your computer has been locked for illegal activity and you have a choice of paying a fine or facing prosecution. According to McAfee, the number of samples of ransomware has grown from 25,000 in the second quarter of 2011, to more than 300,000 in the second quarter of 2013.

Training is a must, but not a cure-all

Lance Spitzner, training director at the SANS Securing the Human Program, gets to phish people every month for a living. He sends phishing emails to his own employees, and to those of organizations as part of the anti-phishing training package.

Without training, up to 60 percent of employees will fall victim to a well-crafted phishing email, he says. With training, that number could go down to as low as 5 percent. But it won’t go down to zero.

“You will never be able to get it perfect, where nobody falls victim,” he says. If people who fall victim report it immediately, however, that’s almost as good. “Now the security team knows they’re under attack, and they know what to look for,” says Spitzner.

Setting up a training program is the easiest thing for companies to do, says Tom DeSot, CIO at San Antonio, Texas-based Digital Defense. But it’s also the hardest. “Many companies do a good job putting in firewalls and intrusion detection systems. They’re focusing on the technical controls. They don’t understand the risk that employees place them at.”

When DeSot attacks an organization, his favorite tactic is to set a webpage that closely mimics the target’s own site. “We send them an email telling them to go and validate their password to make sure they’re following the corporate password policy,” he says.

And people go ahead and click, even though there’s no logical reason for it, he says. “The IT department has tools to do this without even talking to you.”

With training, fewer people click on these links. Without training, says DeSot, “We’ve even had organizations do worse the second year.”

In fact, if employees don’t know what they’re supposed to do with a suspicious email, they might pass the email around to their colleagues, who themselves will click on it to see if it’s legitimate.

“We’ve had organizations where we had hundreds of people click on the link. It’s all company types. Financial, health care, legal, technical – it doesn’t matter, and the size of the company doesn’t matter. In fact, the larger the company, the easier it is. If anybody catches this, typically, it’s the mid-to-small organizations with less than 100 employees.”

Korolov is a freelance writer. She can be reached at maria@tromblyinternational.com

Maria Korolov
Contributing writer

Maria Korolov is an award-winning technology journalist with over 20 years of experience covering enterprise technology, mostly for Foundry publications -- CIO, CSO, Network World, Computerworld, PCWorld, and others. She is a speaker, a sci-fi author and magazine editor, and the host of a YouTube channel. She ran a business news bureau in Asia for five years and reported for the Chicago Tribune, Reuters, UPI, the Associated Press and The Hollywood Reporter. In the 1990s, she was a war correspondent in the former Soviet Union and reported from a dozen war zones, including Chechnya and Afghanistan.

Maria won 2025 AZBEE awards for her coverage of Broadcom VMware and Quantum Computing.

More from this author