zerofox logo
Advisories

ZeroFox Intelligence Assessment – 2023 Phishing Trends

|by Alpha Team

banner image

ZeroFox Intelligence Assessment – 2023 Phishing Trends

Product Serial: A-2023-09-21a

TLP:CLEAR

In this assessment, ZeroFox Intelligence researchers share current phishing trends and recommendations organizations can implement, as well as provide observations on the evolution in the types of phishing tactics most commonly used by increasingly sophisticated cyber attackers.

Standing Intelligence Requirements

Deep Dark Web and Criminal Underground DDW

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:

https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report here

Key Findings

  • Threat actors continue to evolve the techniques leveraged in phishing attacks to overcome security protocols and end-user cyber hygiene practices, as well as to capitalize on contemporary vulnerabilities.
  • Email attachments remain a primary delivery method for malicious software in phishing attacks. Increasingly diverse file types are being leveraged—due in part to a need to circumvent security controls.
  • Threat actors are increasingly exhibiting methods able to bypass multi-factor authentication (MFA) security protocols, including various types of “in-the-middle” attacks, MFA fatigue, and Open Authorization (OAuth) consent phishing.
  • Phishing-as-a-Service continues to proliferate in both dark web marketplaces and private messaging channels, where sellers offer varied, competitive services, and contribute to significantly lowered barriers of entry to threat actors.
  • Search engine platforms are likely increasingly able to mitigate against traditional search engine optimization (SEO) poisoning methods, such as typosquatting and keyword stuffing. However, the threat from SEO cloaking, webpage hijacking, and URL redirecting is likely on an upward trajectory.

Tags: tlp:clear,  phishing & fraud,  all industries,  global