December 2024 Summaries
5 posts from Sublime Security
Filter
Month:
Year:
Post Summaries
Back to Blog
Sublime's Attack Spotlight series provides insights into the email threat landscape by highlighting real-world attack samples, such as recent callback phishing attacks leveraging techniques like Living Off the Land (LOTL) and automatic bulk email redirects. These attacks exploit legitimate services like Microsoft 365 and PayPal by using free, trial, or compromised accounts to send notifications via intermediary distribution lists, keeping the service account from being shut down while maintaining the original sender’s address. Attackers embed callback phishing information in invoices, prompting targets to call a number where the attacker can extract sensitive information. Sublime's AI-powered detection engine identifies these threats through signals such as brand impersonation, engaging language, and unusual sender behavior, thereby preventing these attacks and offering users a way to protect their environment by opening a free Sublime account.
Dec 19, 2024
1,039 words in the original blog post.
Sublime's Attack Spotlight series highlights the growing threat of freight-forwarding scams, which target businesses with sophisticated tactics to fraudulently obtain goods. As traditional scams face increased detection, fraudsters have shifted to exploiting B2B logistics by creating fake companies and utilizing freight-forwarding services to appear legitimate, leading to significant financial losses for suppliers. These scams involve setting up fake companies with lookalike domains, opening accounts with freight-forwarding companies to reroute shipments, and exploiting payment terms to delay detection. Once the fraud is uncovered, scammers dismantle their operations and restart with new identities. Sublime's AI-powered detection engine helps prevent such scams by identifying key signals like unusual sender domains and suspicious behavior, offering a free account to users for protection against these and other email-based threats.
Dec 17, 2024
976 words in the original blog post.
Sublime, a security solutions company founded in 2019, has rapidly gained popularity and recently secured $60 million in a Series B funding round led by IVP, with additional support from Citi Ventures, Index Ventures, Decibel Partners, and Slow Ventures. The company, which began with co-founders who aimed to disrupt an industry reliant on opaque, one-size-fits-all solutions, has achieved success with its transparent, customizable approach that allows customers to self-host and is free for the community. Despite skepticism, Sublime's detection engine has proven effective, demonstrated by its role in protecting the Harris campaign during the U.S. presidential election from email threats. The company has not engaged in traditional marketing efforts, relying instead on word-of-mouth endorsements due to its strong performance and customer satisfaction. As AI-assisted threats escalate, Sublime is committed to innovating in email security, focusing on real-time adaptability and transparency, while continuing to invest in threat research to enhance industry knowledge.
Dec 12, 2024
734 words in the original blog post.
Sublime's recent detection of a malicious SharePoint impersonation led to the discovery of a complex malware delivery attempt involving AutoIT scripts, shellcode, and process injection. The attack started with a deceptive email mimicking a legitimate SharePoint message, luring the target to download a malicious .zip file. Upon analysis, the file contained an AutoIT-based executable, which upon decompilation revealed obfuscated shellcode. Further investigation using tools like CyberChef, Ghidra, and x32dbg identified the presence of process injection techniques and the use of common APIs associated with malware loaders, suggesting a connection to the TrickGate loader and Xloader (Formbook) malware. The analysis highlighted the use of advanced evasion techniques such as loading a second copy of ntdll.dll and employing anti-analysis tricks to defeat emulators and sandboxes, ultimately confirming the presence of Xloader's information-stealing capabilities.
Dec 11, 2024
1,975 words in the original blog post.
AnonymousFox is a threat actor group active since 2019, targeting vulnerabilities in CMS platforms like WordPress, Drupal, Joomla, and OpenCart through tools such as FoxAuto and Fox-CGI, which grant full control over compromised websites for malicious activities including password resets, script uploads, and phishing attacks. Despite available prevention resources, these attacks persist, with recent spikes in activity, leading to compromised sites sending out phishing emails that bypass spam filters. Sublime's AI-powered detection engine effectively identifies and mitigates these threats by analyzing email headers for specific artifacts like "anonymousfox" or "smtpfox," ensuring such malicious messages are kept out of mailboxes. The software uses a combination of open-source detection rules and advanced AI techniques to combat evolving threats, offering users tools to protect their email systems from these persistent attacks.
Dec 04, 2024
571 words in the original blog post.