Phishing has fundamentally changed and its transformation was aided by the blackhole exploit kit. We’ve been blogging about persistent phishing spam runs, including the association of these spam runs with blackhole exploit kits, since earlier this year. We’ve also released a technical paper containing details of our research, which includes the unique insight we have into these events from big data analytics and Trend Micro™ Smart Protection Network™. The paper also includes details about how to effectively protect users.
We’ve been keeping tabs on these events and it is evident that things have changed in the world of phishing. Cybercriminals are no longer relying on users to submit their personal information and they have increased the success rate of their attacks with new methods. Now, the only thing cybercriminals rely on is for users to open an email and click a link.
Old Advice for Phishing
- “Be suspicious of any email with urgent requests for personal financial information.”
- “The email states that you should update your information for one reason or another, and they usually provide a link that you can click to do so.”
- “Avoid filling out forms in email messages that ask for personal financial information”
What has changed?
With the advent of exploit kits, cybercriminals have bypassed the step wherein they rely on users to submit their personal information. In 2012, the major method of attack is to place malware on the user’s computer using exploits and vulnerabilities. Malware, such as ZeuS and Cridex, will silently monitor activity on the computer and look for activity such as logins to financial websites. All they need to make this happen is for a user to click a bad link in email that looks legitimate.
The phishing messages of today have far less urgency and the message is implicit:
- “Your statement is available online”
- “You message is ready”
- “Incoming payment received”
- “Pending Messages: There are a total of 1 messages awaiting your response. Visit your inbox now”
- “Password reset notification”
In many cases these messages are identical to the legitimate messages sent by the legitimate organization. Sometimes, the only difference between the legitimate version of the email and the phished version is the bad link. Read our paper Blackhole Exploit Kit: A Spam Campaign, Not a Series of Individual Spam Runs for more information about these threats and help protect users.