Home / Companies / Sublime Security / Blog / November 2024

November 2024 Summaries

4 posts from Sublime Security

Filter
Month: Year:
Post Summaries Back to Blog
As the holiday season approaches, phishing attacks become more prevalent, exploiting themes like open enrollment, raises, bonuses, and annual reviews to deceive individuals into giving away their credentials. These scams often impersonate familiar entities and use tactics such as authoritative display names, brand impersonation, QR codes, and suspicious attachments to appear legitimate. Sublime, a security platform, detects and prevents such attacks by identifying signals like domain registration dates, BCC'd recipients, and obfuscated JavaScript in email attachments. The article encourages individuals to share their knowledge about these scams with family members during holiday gatherings to help protect them from potential threats and suggests using Sublime for enhanced security.
Nov 27, 2024 997 words in the original blog post.
Sublime's Attack Spotlight series aims to inform users about the email threat landscape by showcasing real attack samples, detailing adversary tactics and techniques, and explaining detection methods. One highlighted attack involves credential phishing via EML attachments in Microsoft 365 emails, where a malicious link is hidden within a fake Microsoft Teams invite. The attack process includes multiple redirects through an open redirect, a Cloudflare Turnstile CAPTCHA, and a fake Microsoft login page, with detection signals such as suspicious EML attachments, short message bodies, and originating from a virtual private server. Sublime's AI-powered detection engine effectively prevents such attacks by identifying key indicators like credential theft language and disposable infrastructure, offering free accounts with customizable threat handling to enhance email security.
Nov 20, 2024 395 words in the original blog post.
Sublime's Attack Spotlight series aims to educate users about email threats, highlighting real-world attacks, adversary tactics, and detection methods. A recent credential phishing attack exploited the trusted Docusign platform to redirect users to a fake Microsoft login page, using high-reputation domains and multiple redirects to evade detection. The phishing attempt includes a fake Microsoft login experience with multiple authentication clicks and CAPTCHA challenges to bypass automated URL analysis. A variant of the attack uses a fake HR email with a QR code to obscure malicious URLs. Sublime's AI-powered detection engine identifies such threats by analyzing suspicious Docusign notifications, new reply-to addresses, and landing pages with phishing indicators. Users can prevent these threats by creating a free Sublime account, which offers customizable protection against credential phishing and other email-based attacks.
Nov 14, 2024 580 words in the original blog post.
Sublime's Attack Spotlight series highlights the evolving email threat landscape by showcasing real-world attack samples, including a recent callback phishing attempt exploiting DocuSign, a trusted business service. This attack exemplifies the growing trend of Living Off the Land (LOTL) tactics, where legitimate platforms are misused to bypass security measures, with attackers sending authentic-looking emails from docusign[.]net, which pass sender authentication. The phishing scheme involves using PayPal brand impersonation and unusual financial transaction details to create urgency and deceive recipients into calling a listed phone number, potentially leading to credential theft. Sublime employs a multi-layered defense strategy using an AI-powered detection engine to identify and prevent such threats, with specific focus on brand impersonation, engaging callback language, and suspicious reply-to addresses. The company encourages deploying their free platform to counteract callback phishing, service abuse, and other email-based threats, while also addressing other attack types like adversarial machine learning extortion, payroll fraud, and business email compromise attempts.
Nov 06, 2024 422 words in the original blog post.