Voice messages and ZIP files could be your biggest security worries

(Image credit: Shutterstock)

The email and data security company Mimecast has released its quarterly Threat Intelligence Report: Risk and Resilience Insights, revealing that the transportation, legal and banking sectors were hit the hardest by cyberattacks during the third quarter of 2019.

The report provides technical analysis from the Mimecast Threat Center from July to September during which time the firm processed 207bn emails, of which 99bn were rejected due to security concerns.

Mimecast's research was focused on observing attack types discovered this quarter through the lens of four main categories: spam, impersonation, opportunistic and targeted. The report found that impersonation attacks are on the rise and they accounted for 26 percent of total detections. However, this category of attacks now also includes voice phishing or “vishing” and this advanced attack uses social engineering to gain access to personal and financial information using the calling capabilities of a victim's smartphone.

Although Mimecast's report discovered many low effort and low-cost attacks targeting its customers, the data also revealed that cybercriminals are launching targeted campaigns which leverage a variety of vectors and last for several days. These sophisticated attacks are likely carried out by organized and determined threat actors who employ obfuscation, layering, exploits and encryption to evade detection.

Volume over sophistication

Of the 160bn emails processed by Mimecast, there were 19 significant malware campaigns identified this quarter including Azorult, Hawkeye, Nanocore, Netwired, Lokibot, Locky and Remcos. The campaigns observed by the firm range from simple phishing campaigns to multi-vector campaigns that alternated file types, attack vector, types of malware and vulnerabilities.

Overall the majority of attacks that took place in Q3 were less sophisticated, high volume attacks and this because these kinds of attacks can be launched by any individual and require less resources to carry out.

Additionally, Mimecast found that ZIP files accounted for 34 percent of file compression format attacks and these attacks are the most detected due to their reliance on human error.

Vice president of threat intelligence at Mimecast, Josh Douglas provided further insight on the report's findings, saying:

“Threat actors seek numerous ways into an organization - from using sophisticated tactics, like voice phishing and domain spoofing, to simple attacks like spam. This quarter’s research found that the majority of threats were simple, sheer volume attacks. Easy to execute, but not as easy to protect against as it shines a very bright light on the role human error could play in an organization’s vulnerability. Organizations need to take a pervasive approach to email security - one that integrates the right security tools allowing for greater visibility at, in and beyond the perimeter. This approach also requires educating the last line of defence – employees. Coupling technology with a force of well-trained human eyes will help organizations strengthen their security postures to defend against both simple and sophisticated threats.”

TOPICS
Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
Webex by Cisco banner on a Chromebook
Cisco warns some Webex users of worrying security flaw, so patch now
Red padlock open on electric circuits network dark red background
AI-powered cyber threats are becoming the biggest worry for businesses everywhere
Woman using iMessage on iPhone
Apple to take legal action against British Government over backdoor request
Red padlock open on electric circuits network dark red background
Aviaton firms hit by devious new polyglot malware
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
Major ransomware attack sees Tata Technologies hit - 1.4TB dataset with over 730,000 files allegedly stolen
Image of laptop infected with malware
Ransomware criminals are now sending their demands...by snail mail?
Latest in News
AMD Ryzen 9950X
Ryzen CPUs are the cheapest Zen 5 cores you can buy, but I was surprised to see this AMD 192-core CPUs on the value leaderboard
A hand holding a phone showing the Android Find My Device network
Android's Find My Device can now let you track your friends – and I can't decide if that's cool or creepy
Insta360 X4 360 degree camera without lens protector
Leaked DJI Osmo 360 image suggests GoPro and Insta360 should be worried – here's why
A YouTube Premium promo on a laptop screen
A cheaper YouTube Premium Lite plan just rolled out in the US – but you’ll miss out on these 4 features
Viaim RecDot AI true wireless earbuds
These AI-powered earbuds can also act as a dictaphone with transcription when left in their case
The socket interface of the Intel Core Ultra processor
Intel unveils its most powerful AI PCs yet - new Intel Core Ultra Series 2 processors pack in vPro for lightweight laptops and high-performance workstations alike