Press release
KnowBe4 Alert: Cyber Criminals Switch to Malicious HTML Attachments
While ransomware attacks and new strains explode, organizations are reminded to be aware of new forms of social engineering that leave them open to attack(Tampa Bay, FL) May 12, 2016-- KnowBe4, the US’s most popular security awareness training and integrated phishing platform, warned customers this week of a new wave of social engineering tactics being introduced by cyber criminals. While ransomware continues to surge, a new form of social engineering attack is showing up and bypassing antivirus and secure email gateway products: malicious attachments using the HTML format which is used by banks for secure messaging.
KnowBe4’s phish-alert button (free plugin for Outlook, Office 365, Gmail and Notes) allows users to send suspicious phishing emails to IT or an internal incident response team with just one click. From these alerts, KnowBe4 analyzes which phishing attempts are making it through all the filters.
Over the past six to nine months .DOC and .JS file attachments have dominated the news surrounding the rise in phishing attacks. The reasons are obvious and understandable: those two file types (usually packaged in .ZIP files) are commonly used to deliver extremely dangerous ransomware and banker trojans. However, employees should be trained to be wary of another file type that now can be a malicious attachment: .HTML files.
KnowBe4 CEO Stu Sjouwerman said, “Fresh KnowBe4 Lab analysis shows that although not nearly as prevalent as .JS and .DOC file attachments, .HTML attachments are now potentially dangerous enough that we alert our customers and organizations in general to adjust their email gateway filters to include .HTML attachments if possible, and train their users to be aware.”
HTML attachments are commonly used by financial institutions to deliver secure documents and messages as well as to enable users to conduct banking business in a secure environment. HTML attachments we've analyzed recently have typically been used for a very prevalent phishing attack: the credentials phish, aimed at tricking users into believing they are being asked to log in to a trusted online institution. The login form they see, though, is fake, and the usernames and passwords they enter are quietly being harvested by the bad guys for future exploitation.
• Bank credentials phishes are a familiar affair. The email body warns recipients of some urgent problem or issue requiring them to log in to their online bank accounts. The HTML pages used for these phishes more often resemble the targeted bank's home page than any actual HTML attachment used by a bank.
• The bad guys also spoof popular online services, creating login pages that are nearly indistinguishable from the real thing. However, not all spoofed login forms are service or brand specific. KnowBe4 has seen an increasing number of brand-agnostic email login forms, delivered both as .HTML attachments and live online web pages. Although this .HTML attachment prominently features the Google brand, it advertises to victims that the form will accept credentials for any manner of email address or account. Users could easily use their work email logins, opening a door directly into their employers' corporate networks.
• Bad guys often use the ruse of spoofing a secure document or message delivery service to trick users into opening potentially malicious file or coughing up secure credentials. Such as use of an Adobe ID login.
Sjouwerman also noted, “Your best defense is to educate users. Employees who aren't security awareness trained often work with relatively simple models of how the online threat landscapes operate. While many users may recognize that .EXE and .PDF files are potentially dangerous or "bad," those same users will likely regard .HTML attachments as harmless and "good." Employees need to be educated about the wide variety of potentially malicious email attachments -- including .HTML attachments -- they may encounter in their inboxes.”
Effective training and frequent simulated phishing attacks are a vital step managing the problem of social engineering and enabling employees to recognize and correctly respond to the actual threats they will encounter.
For more information visit: www.KnowBe4.com
About KnowBe4
KnowBe4 is the world’s most popular integrated Security Awareness Training and Simulated Phishing platform. Realizing that the human element of security was being seriously neglected, KnowBe4 was created by two of the best known names in cybersecurity, Kevin Mitnick (the World’s Most Famous Hacker), and Inc. 500 alum serial security entrepreneur Stu Sjouwerman, to help organizations manage the problem of social engineering tactics through new school security awareness training. The company maintains a top spot in the Cybersecurity 500, the definitive list of the world’s hottest and most innovative companies in cybersecurity. More than 3,500 organizations use KnowBe4’s platform to keep employees on their toes with security top of mind. KnowBe4 is used across all industries, including highly regulated fields such as finance, healthcare, energy, government and insurance.
KnowBe4
33 N Garden Ave, Clearwater, FL 33757
Contact: Kathy Wattman, KnowBe4
kathyw@knowbe4.com | (727) 474-9950
Media Contact: Michael Becce, MRB Public Relations, Inc.
mbecce@mrb-pr.com | (732) 758-1100 x104
MRB Public Relations
2 East Main Street, Suite 3, Freehold, NJ 07728
This release was published on openPR.
Permanent link to this press release:
Copy
Please set a link in the press area of your homepage to this press release on openPR. openPR disclaims liability for any content contained in this release.
You can edit or delete your press release KnowBe4 Alert: Cyber Criminals Switch to Malicious HTML Attachments here
News-ID: 341690 • Views: …
More Releases from MRB Public Relations
Digital Defense, Inc. and UTSA Partnership Facilitates Cybersecurity Career Read …
(San Antonio, July 23, 2019) – Digital Defense, Inc. and The University of Texas at San Antonio (UTSA) Department of Computer Science jointly announced today a partnership that will provide students and faculty with access to an award-winning cloud-based information security platform to further enrich the students’ cybersecurity education.
UTSA students and faculty will be able to utilize Digital Defense’s flagship Frontline.Cloud™ platform to evaluate the security posture of applications, systems…
SQUAN Launches New Technical Division to Serve Complex Network Infrastructure Co …
Former Verizon Rockstar, Anand Gandhi, Joins SQUAN to Lead
New Wireless Technology Division
Englewood, New Jersey – July 1, 2019 – SQUAN, an industry leader specializing in telecommunications design/build services for network infrastructure, announced today the appointment of Anand Gandhi as CTO and leader of its newest division, SQUAN Technology.
As CTO of SQUAN’s wireless technology division, Gandhi will develop and grow the technology group by expanding engineering services to…
Imagination Park Executes Agreement to Bring Augmented Reality Experiences to Fl …
Metro Group Miami working closely with Leaders of the Florist Marketplace
Vancouver, CANADA – June 27, 2019 – Imagination Park Technologies Inc. (CSE: IP) (OTC: IPNFF), the company bringing augmented reality (AR) experiences to consumers and retailers, today announced that Field of Flowers in Davie, Florida has signed a deal that will look to bring unique augmented reality experiences to consumers in South Florida. Field of Flowers is among the largest…
Keyfactor and Thales Address Code Signing Cyber-Attacks Targeting Businesses
Security leaders announce industry-first code signing product
CLEVELAND, Ohio, June 17, 2019 – Keyfactor, a leading provider of secure digital identity management solutions, today announced a new integration with Thales that combines Keyfactor’s code signing platform with the high-assurance key protection of Thales’ SafeNet Cloud HSM On-Demand. The result of this partnership, KeyfactorTM Code Assure, delivers secure code signing to software vendors, mobile app developers, enterprise IT organizations, and manufacturers of…
More Releases for KnowBe4
V3iT and KnowBe4 Join Forces to Empower Businesses with Comprehensive Cybersecur …
V3iT, a leading provider of advanced IT security solutions, and KnowBe4, one of the world's leading provider of security awareness and training platform, today announced a strategic partnership to deliver a comprehensive cybersecurity solution for businesses of all sizes. This collaboration combines V3iT's expertise in network and endpoint security with KnowBe4's industry-leading security awareness training platform, empowering businesses to build a robust defense against evolving cyber threats.
Addressing the Human Factor…
KnowBe4 Expands Team to Include Security Awareness Advocate
KnowBe4 hires Security Awareness Advocate in answer to growing demand and explosive growth.
Tampa Bay, FL (August 30, 2016) -- KnowBe4, America’s most popular security awareness training and simulated phishing platform, has hired Security Awareness Training Advocate Erich Kron to support and expand its growing leadership position. Kron is a veteran information security professional with over 18 years’ experience in the medical, aerospace, manufacturing and defense fields and a well-versed speaker.…
KnowBe4 Makes Security Awareness Training Available in 26 Languages
KnowBe4 combats the exploding threats of ransomware and CEO email fraud giving companies a global tool to manage risks associated with social engineering
KnowBe4 Inc., the most popular integrated platform for security awareness training and simulated phishing tests, released its Kevin Mitnick Security Awareness Training in twenty-six language versions. The interactive, on-demand computer-based training covers high-risk topics and how to identify red flags such as the current ransomware epidemic, the W-2…
KnowBe4 Has Explosive Year-Over-Year Growth of 454% for Q2 2016
Company sees demand accelerating for its integrated security awareness training and phishing platform
(Tampa Bay, FL) July 5, 2016 --- KnowBe4, America’s most popular integrated security awareness training and phishing platform announced its explosive year over year growth of 454% for Q2 2016, with a record number of 655 new corporate accounts in June alone, rising to nearly 5,000 enterprise accounts combined with a very robust 86% customer retention rate.…
KnowBe4 Releases Results of 2 Year Survey Showing Rising Concern over Ransomware
Security Awareness Training and Backup Deemed Most Effective to Combat Ransomware
(Tampa Bay, FL) June 22, 2016 -- A new survey by KnowBe4, the US’s most popular security awareness training & integrated phishing platform shows the growing volume of ransomware victims despite increased efforts to prevent it. 1138 companies across a variety of industries participated. The study compares levels of concern over ransomware from 2014 to 2016
The results showed there is…
KnowBe4 CyberAlert: Double-Barrel Ransomware and DDos Attack in-one
(Tampa Bay, FL) May 24, 2016-- KnowBe4, issued an alert today on a malicious new trend in ransomware. Instead of "just" encrypting data files on a workstation (plus any network drive it can find) and locking the machine, a new variant of the Cerber ransomware is now adding a DDoS bot that can quietly blast spoofed network traffic at various IPs.
This is the first time DDoS malware has…