Latest SBA phishing attempt: stealthy social engineering phish using newly registered domains attempts to gain bank details
Blog post from Cloudflare
Cyber criminals are exploiting the confusion surrounding the US Small Business Administration's (SBA) loan application procedures amidst the pandemic by impersonating the SBA in Coronavirus-themed phishing messages. These attacks involve a clever social engineering tactic that can fly under almost any radar, with malicious actors opting for a silent attack vector relying on targets believing the email is indeed from the SBA. The latest wave of attacks does not contain any malicious payloads but only a benign attachment named SBA - Disaster Loan Assistance Form.pdf. To thwart these sneaky SBA-themed phish, Area 1 Security uses multiple advanced techniques that leverage insight gained from early identification of attacker campaign infrastructure, enabling superior detection of emails from spoofed domains and accounts.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Real-time | 2 | 629 | 236 | 77 | +1% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.