BotNet News

Your source for Online Security News

Phishing is a tactic used by criminals to steal personal information, including login credentials and passwords. It often involves tricking victims into clicking links or downloading attachments, but it can also involve malware and spoofing websites. Attackers can use personal details found on social media to make phishing messages more convincing. In addition, if an employee clicks on a suspicious link or visits a phishing website on a work-related device, the company could be held liable for cyber crime.

In modern phishing attacks, attackers take advantage of various technologies to deliver malware and spoof legitimate websites. They might exploit emotions such as curiosity, greed or fear in order to lure victims into taking action. Often, attackers use techniques like open redirects to mask malicious links and make them appear valid to humans and spam filters. Other common tactics include using a shortened URL, encrypting the URL in order to hide it from spam filters and injecting HTML into emails in order to conceal malicious scripts.

During the last year, Hoxhunt has monitored a spike in calendar phishing attacks targeting marketers and social media administrators. These attacks utilize a technique known as “clone phishing” to exploit trust by mimicking a genuine calendar invitation file format (.ics). The resulting phishing emails typically contain meeting links and attachments that are designed to hijack email environments and steal credentials.

The best way to prevent phishing is to always think before you act. Delete suspicious messages and consider reporting them to help protect yourself and your organization. It’s also a good idea to run a full security scan of all devices and change any passwords associated with compromised accounts, ensuring multifactor authentication is enabled.