Did you think phishing campaigns were passé? Well, what’s past is prologue. Phishing attacks, which have increased 30 percent in each of the last three years, are still responsible for most data breaches. Here’s how to understand and prevent them from crippling your organization.
The SecureWorks Counter Threat Unit (CTU) reported that the North Korean cybergang, Lazarus, targeted financial executives of cryptocurrency companies with the lure of a job opening for a chief financial officer at another cryptocurrency firm. The cyberfraudsters successfully infiltrated scores of computers via enticing emails. When victims opened Word attachments in the phishing emails they were presented with a pop-up message encouraging them to accept “Enable Editing” and “Enable Content” functions. The document then embedded a malicious macro that created a separate professional-looking, LinkedIn-style, CFO job-lure document and installed a remote-access Trojan [through which the fraudsters could download additional malware to steal cryptocurrency and personally identifiable information (PII)]. (See
Secureworks Discovers North Korean Cyber Threat Group, Lazarus Spearphishing … Dec. 15, 2017.)