Thus far in 2018, PhishMe Intelligence™ has observed a lull in multiple malware families that were prominent throughout 2017. There are several possible reasons for this hiatus.
In October of 2017 we blogged about a phishing campaign specifically targeting Brazilian Portuguese- speaking users.
Back then, the campaign distributed a malicious Chrome browser extension. More recently, we have observed a wave of emails that have remarkably similar characteristics. This time around, the malware of choice is a banking trojan.
With security analysts pulled in many directions, they must be able to prioritize and invoke incident response on ransomware, business email compromise (BEC), malware infections, and credential-based theft emails. The key to this is the automation and streamlining of the incident response. PhishMe Triage™ has been updated with new features to help security analysts and incident response teams streamline their processes and secure administrative access.
Key Features this Release
- Tighter Integration – Authenticated API for integration across the incident response team
- Additional Security – Two-factor authentication for PhishMe Triage users
- More Accountability – Audit logs are generated for all users of PhishMe Triage
- Better Visibility – System status alerts can be distributed via syslog
The new API is designed to help PhishMe Triage interact with other systems across the incident response process. This authenticated API enables other systems to “talk” to PhishMe Triage to automate the process and get the right teams involved, faster. The fully documented REST API can be used to pull information from PhishMe Triage on emails, clusters, attachments, reporters, integrations, health stats and more. The API can be used in the preprocessing stage to notify malicious attachments at soon as they are reported. Join the conversation in the PhishMe Community PhishMe Triage API discussion to share ideas and code samples for building solutions using the API.
This release adds in an additional layer of security for PhishMe Triage users. Two-factor authentication can be turned when a user logs in to PhishMe Triage. End users will install a standard two-factor authentication app on their mobile device, and then simply scan a QR code to register their phone with PhishMe Triage. At log in, they will be prompted for code generated by the app. This makes authentication based upon “something you know”, the password, and “something you have”, the app. There is support Google Authenticator and other two-factor tools.
This release also introduces audit logging in PhishMe Triage. With the audit log, visibility about who did something in PhishMe Triage, what they did and when they did it is captured. The audit log tracks over 145 Event ID’s across PhishMe Triage. This enables the tracking of all of the actions users of PhishMe Triage. These logs can be viewed directly inside of PhishMe Triage, or exported to another tool for more analysis.
This release also extends syslog alerting with PhishMe Triage. With syslog enabled, PhishMe Triage can send out alerts to other systems. Syslog alerts can be used to share information like the cluster velocity, operational SLA alerts, platform health, ingestion health and triage recipe monitoring. This enables PhishMe Triage to share alerts across the entire incident response team.
If you have any questions, please email email@example.com. Full details on the release are available in PhishMe Community. To access it, simply log in to your PhishMe Triage appliance and then click the “Visit PhishMe Community” icon.
Don’t ever miss another threat – sign up for PhishMe® Threat Alerts today and receive updates on new and emerging phishing and malware threats, completely free.
When considering your organization’s response to a simulated phish, it is critical to understand that we are emulating / practicing for real life events with the purpose of conditioning appropriate response patterns in our user base.
PhishMe has been named a consecutive leader in Gartner’s 2017 Security Awareness Computer-Based Training Magic Quadrant. It’s the second year we’ve been recognized as a leader and positioned highest in “ability to execute.”
In early 2017, the Sage ransomware distinguished itself with a fresh take on the business model for criminal ransomware operations. Built with an engaging, intuitive user interface for requesting the ransom payment, it also reinforced the fact criminals are willing to invest in developing new versions of established ransomware tools. Sage has reasserted itself as a relevant player on the already-saturated ransomware threat landscape with version 2.2.
PhishMe®’s Phishing Defence Centre has observed multiple emails with a subject line that includes a reference to tax declarations in Switzerland (Original subject in German: “Fragen zu der Einkommensteuerklaerung”) as shown in Figure 1. The sender pretends to be a tax officer working for the tax administration (Eidgenoessische Steuerverwaltung ESTV) and is asking the victim to open the attached file to answer questions about the tax declaration.
Part 4 in a weekly blog series, “How Attackers Target Trust,” running during October, National Cyber Security Awareness Month and European Cyber Security Month.
Over the past decade, mobile phones and social media have become essential to how we ingest news and communicate friends and families.