1 min read

New Phishing Attacks Use HTML Email Attachments

HTML attachments as an attack vector may seem a little old school. However, according to statistics compiled by Kaspersky Lab indicates that in 2022, that form of attack is not just simply still being employed, but hackers are making surprisingly regular use of it.  The security company detected more than two million emails of this kind targeting Kaspersky customers in the first four months of the year (2022).

The specific breakdown of monthly instances looks like this:

  • January 2022: 299,859 instances
  • February 2022: 451,020 instances
  • March 2022: 851,328 instances
  • And April 2022: 386,908 instances

The researchers aren’t clear on exactly what caused the huge spike in March but they note that it returned to expected levels the month following.

Using HTML attachments as an attack vector saw a big spike in 2019 and then it seemed to fall out of favor. The number of instances dropped markedly and prompted some security researchers to conclude that, based on current trajectories, the attack vector was on the way out.

The last four months seem to have disproved that notion and HTML attachments are back in fashion in the underbelly of the web.

It’s important to remember that merely opening these files is in many cases enough to have JavaScript run on your system. That could lead to the target system being hijacked using a malware-assembly-on-disk scheme that could allow it to bypass antivirus software entirely.

This isn’t something that gets mentioned very often in employee email safety training, but it should be.

As ever, the best defense against any type of phishing attack is to treat any incoming email message from a sender you don’t know with a healthy dose of skepticism. If that email contains an attachment, those attachments should be treated even more skeptically. If you’re looking for cybersecurity and phishing protection on the West Coast, contact Heroic Tech today!

Used with permission from Article Aggregator

An AI Agent Ran a Ransomware Attack. Alone. The Real Story Is the Aftermath

An AI Agent Ran a Ransomware Attack. Alone. The Real Story Is the Aftermath

The first AI-run ransomware attack wasn't the story. What followed, and what it means for every organization deploying AI agents, is.

Read the full blog
Your IT Provider's Response Time Promise Is Only Worth What They Deliver

Your IT Provider's Response Time Promise Is Only Worth What They Deliver

Your IT provider's response time promise is only worth what they actually deliver. Here's how to read your SLA, what good looks like, and how to...

Read the full blog
Microsoft Copilot vs. ChatGPT for Business: Same Prompt, Very Different Answer

Microsoft Copilot vs. ChatGPT for Business: Same Prompt, Very Different Answer

Most businesses treating Copilot and ChatGPT as substitutes are using at least one wrong. Here's what each is built for and how to choose.

Read the full blog

The Rising Threat of Cyber Attacks: A Modern Challenge

Cyber threats have evolved from basic spyware in the early 2000s to today's advanced attacks using techniques like ransomware and phishing.

Read the full blog

Common Aspects of Phishing Attacks

Phishing attacks, despite their ever-evolving tactics and techniques, all share a common thread that connects them.

Read the full blog
How to Prevent Phishing Attacks: Cybersecurity Tips for Lawyers

How to Prevent Phishing Attacks: Cybersecurity Tips for Lawyers

Learn cybersecurity tips for lawyers to protect client data, stop phishing attacks, and strengthen your law firm’s defense.

Read the full blog