You spoke, we listened: What’s new for CBFree
May 12, 2016 by Cofense in Internet Security AwarenessYou spoke…we listened. PhishMe CBFree Computer Based Learning modules launched in October 2015 and was extremely well received among users. As an initial launch, we listened heavily to our customer’s feedback and have a new set of modules.
PhishMe’s Gary Warner Featured in Threat Intelligence Thought Leadership Interview on Recorded Future
May 4, 2016 by Cofense in Cofense NewsThreat IntelligenceThis week, Recorded Future published another segment in their recent “Threat Intelligence Thought Leadership Series” featuring PhishMe’s Chief Threat Scientist Gary Warner. The article titled Why You Should Launch a Threat Intelligence ‘Hunt’ Team covers a variety of perspectives on threat intelligence, from driving factors in today’s threat intelligence community, actionable intelligence trends and even advice for aspiring threat intelligence analysts on how to navigate today’s information security landscape.
University W2 Phishing and CEO Impersonation
April 13, 2016 by Cofense in PhishingAt PhishMe we talk frequently about a familiar concept that cyber attacks and phishing emails are very rarely sent to only one organization. While security teams tend to focus on threats to your organization, PhishMe Intelligence is watching for email-based threats for EVERY organization. As we were gathering information about tax-related phishing scams this year, we noticed that institutes of higher learning were being hit quite broadly by this year’s W2 related scams.
RockLoader – New Upatre-like Downloader Pushed by Dridex, Downloads all the Malwares
April 12, 2016 by Cofense in PhishingOn 4/6, the Phishing Intelligence team came across a wave of phishing emails that contained a .js file packaged inside of a zip file used to deliver malware. This is nothing new, and has been seen being pushed out by resources associated with the Dridex botnet and the Locky encryption ransomware. The interesting piece is that the attackers are using a new piece of malware called RockLoader to download and install the malware on remote systems. Downloaders are nothing new, as Upatre was used with Dyre and Gameover ZeuS in the past. RockLoader has several tricks up its sleeve.
Cofense April Cybercrime Alert: Ransomware Attacks Expected to Increase
March 31, 2016 by Cofense in PhishingPress ReleasesCybersecurity Experts, Former Federal Law Enforcement Professionals Say Cryptocurrency, Digital Data and Vulnerable Employees May Fuel Largest Crimewave in Modern History LEESBURG, Va. – March 31, 2016 – PhishMe Inc., the leading provider of human phishing defense solutions, today released its April Cybercrime Alert, warning all organizations that its threat researchers expect ransomware attacks to increase as cybercriminals become increasingly aware that: Ransomware is readily-available and changes faster than detection technologies can respond In most cases, paying the ransom is the only way to free hostage data and systems Recent successful ransom situations will only encourage more attempts Cryptocurrencies such...
Tax Time is Phishing Time: Here’s How to Help!
March 31, 2016 by Cofense in PhishingImportant disclaimer: THE IRS DOES NOT INITIATE CONTACT WITH TAXPAYERS BY EMAIL, TEXT MESSAGE, OR SOCIAL MEDIA CHANNELS TO REQUEST PERSONAL OR FINANCIAL INFORMATION. (See: https://www.irs.gov/uac/Report-Phishing ) The IRS has a very active security team, currently part of the U.S. Treasury Inspector General for Tax Administration (TIGTA), that is responsible for fighting phishing and tracking down the criminals who prey on U.S. tax payers. If you believe you have received a Phishing email, please help them by reporting the email you received to [email protected] Additionally, please also consider sending a copy to our team. PhishMe Brand Intelligence automatically processes any URLs...
Reclaiming the Edge in the Battle Against Phishing Attackers
March 15, 2016 by Cofense in PhishingThere is a reason that most data breach incidents involve phishing attacks: phishing works. Attackers know that it is far easier to gain access to a protected network by tricking people into clicking on malicious links and attachments than it is to penetrate sophisticated firewalls and intrusion detection systems. And they know that they have an edge over the defenders because they only have to win once to gain access. As defenders, we need to stop them every time. We can’t prevent attackers from soliciting people with phishing emails. But we can take away their edge.
Cofense CTO Aaron Higbee Discusses Ransomware Dangers on CNBC SquawkBox
March 14, 2016 by Cofense in PhishingAaron Higbee, PhishMe co-founder and CTO, was featured on a recent CNBC SquawkBox broadcast segment discussing recent ransomware trends plaguing the healthcare space. During the attack, a phishing email is sent to the user’s inbox prompting them to click a malicious link that begins encrypting files and storage drives on your computer. Once the files are encrypted, the only way to retrieve the data from the malicious actors is to pay a ransom in BitCoin. In the video (seen below), Higbee dives deeper into the various motivations for these types of attacks and how businesses can better prepare themselves to...
Ransomware Rising – Criakl, OSX, and others – PhishMe Tracks Down Hackers, Identifies Them and Provides Timeline of Internet Activities
March 10, 2016 by Cofense in PhishingOver the last few months, the Phishing Intelligence team has observed a huge increase of ransomware. Many attackers are starting to experiment with ransomware as an alternative to quickly monetize. Dridex has employed a new family of ransomware named Locky, which is a pretty drastic shift in what this group is known for doing. We’re even seeing attackers go after OSX with ransomware, something that was once thought to be immune from malware, however there were nearly 6,500 users who downloaded the compromised BitTorrent client. Follow along with us as we deconstruct a recent ransomware attack and hack the hackers behind the...