Photo Showing Gmail Inbox Pane
© Jasni/Shutterstock.com
No AI-generated content: this article is written and researched by humans
Table of contents

Cybercriminals are increasingly using popular websites like YouTube, Google Docs, and Amazon to deliver malicious payloads and bypass domain-based inspection. According to a new report, there was a 121 percent increase in this practice between Q4 2022 and Q1 2023.

Egress also announced a 51 percent increase in phishing messages sent from compromised email accounts and other phishing attacks targeting the C-suite.

Egress’ Email Threats Pulse Report, published on May 25, casts a wide lens on the cyber threat landscape, highlighting emerging tactics among cybercriminals and outlining ways cybersecurity experts can defend against these evolving threats.

Egress underlined the need for adaptive email security systems to stop these threats.

Trusted Websites Used to Deliver Malicious Payload

According to Egress’ report, in the first quarter of this year, the top ten websites abused in phishing attacks were Firebase Storage, Amazon AWS, YouTube, SharePoint, Box, Google Docs, Ticketmaster, Proton Driver, One Drive, and DocuSign.

Impersonating these websites or hiding malicious links in seemingly harmless content, such as videos or documents on trusted websites, allows cybercriminals to go undetected and snare unsuspecting victims.

In one example, Egress revealed how cybercriminals used a spoofed Ticketmaster email address to send a phishing email containing a hyperlink. When victims click on the link, they’re redirected to a phishing website and prompted to provide their credentials.

“This phishing campaign has been commoditized by crime-as-a-service gang Caffeine and is available to purchase online as a phishing kit,” Egress said.

Egress also revealed another instance where cybercriminals abused YouTube’s attribution links feature that allows content creators to embed hyperlinks within videos. When targets click the link, they’re redirected to a Google login page hosted on a static Amazon S3 bucket.

“Our analysis of the attack reveals that the cybercriminals appear to be using accelerated mobile pages (AMP), which helps the redirect to the S3 bucket go unnoticed,” Egress said.

The report also cites instances of cybercriminals using Google Docs, SharePoint, and OneDrive to distribute malicious links.

“The best way to get a phishing hyperlink to pass standard link checks (such as age, blocklist, and lookalike checks) is to use a legitimate website and even hide the payload behind a log-in screen,” the report said.

Egress also revealed that cybercriminals tend to send phishing emails to C-Suite at the beginning of the week.

“Analyzing the volume of phishing attacks targeting the entire C-Suite across the span of a week reveals they are most likely to receive phishing emails on a Monday (27%) and least likely to receive them on a Sunday (6%) and Wednesday (9%),” Egress revealed.

On Mondays, people are catching up and starting the week, increasing the risk of mistaking a phishing email for a legitimate one. With reduced corporate mail on Saturdays, phishing emails are likely to be more visible, the report explained.

Defending Against Novel Phishing Attacks

Egress recommends organizations implement cloud email security solutions that utilize artificial intelligence security.

Organizations “need to ensure that their email security tech stacks include solutions that use natural language processing (NLP) and natural language understanding (NLU), which are AI models that analyze the language contained in emails to detect social engineering,” Egress said in an email to VPNOverview. The company also advocated for the use of machine learning to detect anomalous behavior.

For individuals, Egress recommends verifying links and attachments and using secure passwords across accounts.

As long as you have an email address, you’ll likely receive phishing emails. Cybercriminals often impersonate popular brands to lure victims into clicking on malicious links. We’re reported on scammers impersonating various brands, including Pfizer and PayPal. It’s essential to use a good antivirus solution to detect these malicious files and sites in real time.

Leave a comment