Home / Companies / Sublime Security / Blog / April 2023

April 2023 Summaries

2 posts from Sublime Security

Filter
Month: Year:
Post Summaries Back to Blog
Business Email Compromise (BEC) attacks are sophisticated cybercrimes targeting organizations of all sizes by impersonating trusted figures to trick employees into unauthorized transactions or revealing sensitive information. These attacks are challenging to detect with traditional security measures due to their customized nature and the absence of typical malicious payloads. Advanced technologies like Natural Language Understanding (NLU) offer a powerful defense by analyzing email content to identify potential threats through intent classification and Named Entity Recognition (NER). By integrating NLU with Message Query Language (MQL), organizations can rapidly adapt their defenses against BEC attacks by identifying deceptive language patterns and suspicious signals, such as impersonation or urgency. This comprehensive approach enhances the security of digital environments, protecting organizations from financial and reputational harm caused by cyber threats.
Apr 18, 2023 1,093 words in the original blog post.
QakBot, also known as QBot and Pinkslipbot, is a notorious banking Trojan that has been evolving since its inception in 2007, initially designed to steal financial data and login credentials. Over the years, it has employed various infection techniques, including malspam campaigns and, more recently, the use of Windows Script Files (.wsf) for payload delivery, which involves executing malicious code through a complex sequence of files. To combat QakBot's evolving methods, a multi-layered detection and prevention strategy is recommended, such as leveraging MQL rules to identify suspicious email attachments and implementing Attack Surface Reduction (ASR) techniques to minimize potential attack vectors. These strategies include scanning emails for suspicious links, detecting disk images in encrypted zip files, and identifying malicious commands in OneNote attachments, all of which aim to reduce the risk of malware exploitation. These detection rules and techniques are incorporated into the Sublime Rules Feed, providing users with enhanced protection against QakBot and similar threats.
Apr 12, 2023 849 words in the original blog post.