This page was machine-translated and may differ from the original. View original

The high-tech industry is exposed to domain and variant kit attacks.

Google 우선 소스Published2019.11.11 10:13
Akamai Releases 2019 State of the Internet Report
Targets include Microsoft, PayPal, and Dropbox.
Following the financial services, e-commerce, and media industries



Phishing attacks, such as corporate email compromises, are constantly evolving and threaten various industries around the world.
Akamai

Akamai Korea, which provides an intelligent edge platform, has released the 'Akamai 2019 Internet State Report, Security Phishing'.

According to the report, cybercriminals are exploiting the world's largest technology brands through enterprise-based development and deployment strategies, such as phishing-as-a-service (PaaS). Of these, 42.63% of domains targeted Microsoft, PayPal, DHL, and Dropbox.

Phishing attacks are constantly evolving, employing a variety of techniques and are no longer confined to email-based threats. They are now expanding to include social media and mobile devices, creating a widespread problem that impacts all industries.

One such technique is a Business Email Compromise (BEC) attack. According to the FBI, BEC attacks resulted in over $12 billion in losses worldwide between October 2013 and May 2018.

Cybercriminals are targeting prominent global companies and their users through organized and sophisticated phishing campaigns. The industry most affected by phishing attacks was the high-tech industry, with 6,035 domains and 120 variant kits discovered in 2019.

Next, 3,658 domains and 83 variant kits were discovered in the financial services industry, followed by e-commerce (1,979 domains and 19 variant kits) and the media industry (650 domains and 19 variant kits).

By company, the order was Microsoft 21.88% (3,897 domains, 62 variant kits), PayPal 9.37% (14 variant kits), DHL 8.79% (7 variant kits), and Dropbox 2.59% (11 variant kits).

“Short activation periods for phishing kits are becoming increasingly common in phishing attacks, as phishing attackers continually evolve to remain undetected for as long as possible, and attackers continue to develop new bypass methods to keep their kits undetected,” an Akamai representative said. “We found that 60% of the phishing kits observed this time were only active for up to 20 days.”

“Phishing is a long-term problem that will continue to impact consumers and businesses until individuals become more aware and layered defenses are in place,” said Martin McKeay, senior editor of the Akamai State of the Internet / Security report. “As the phishing landscape continues to evolve, techniques like BEC attacks are developed, and threats to various industries around the world arise, businesses must constantly strive to stay ahead of corporate criminals who seek to exploit their trust.”

This report also describes a research project that tracked the daily workflow of a phishing kit developer who provided three types of kits featuring cutting-edge evasion techniques, designs, and geo-targeting options. Targeting global corporations and offered at low prices, these kits are attractive items that lower the barrier to entry for phishing attackers.

This Akamai 2019 State of the Internet Report is available for download on the Akamai website.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.
최인영 기자