The majority of us have been through phishing training for our jobs, where the simplified best-practices for all employees are laid out. These usually include reporting to IT when you receive emails from suspicious accounts, those that contain links without a description or subject lines that don’t make sense, or content you’re not familiar with or normally asked for, among other questionable communication.
So what happens when a dangerous phishing email doesn't include any of the characteristics you’re told to look out for? A recent phishing attack revealed just how sneaky, and devastating email attacks can be with a new “worm” technique from hackers.
Living in plain sight
During a recent worm phishing attempt reported at an organization remaining anonymous, recipients opened scam emails without hesitation because the sender addresses were from real employee accounts that had been compromised. The emails were sent in response to an email chain the malicious actors identified as recent, and were those where the receipts would be expecting a link in response. The emails from compromised accounts weren’t sent out of context, weren’t asking for anything out of the ordinary, and were a part of an existing conversation.
While hacking attempts like this aren’t yet prevalent because they require more effort on the part of the bad actor to gain access to someone's account and read through their recent email conversations manually, the effectiveness of constructing emails that make sense in context to the receiver goes way beyond those of your usual phishing attempt. Infiltrating just one organization with worm emails gives malicious actors access to the vendors and outside organizations in their network, so it’s hard to tell where the damage ends from any one email.
The wildfire spread
Because the emails received were so believable, the number of recipients who clicked into the compromised link was higher than a normal phishing attack, with the number of compromised accounts exponentially increasing almost immediately. As more and more employees fell for the scam, more accounts were accessed and in turn, more phishing emails were sent out across the company and more personal passwords and protected information were compromised.
The malicious actors of course didn’t just limit their targets to internal company communication, they sent the worm emails to chains including business partners, third party vendors, and other external chains. That’s how the company believes the initial account was compromised internally: the first employee clicked on the bad link when it was sent to them by an outside vendor.
Despite the initial panic at the large volume of compromised accounts, the IT department was able to track down the shared URL pattern among all of the phishing links being sent, and succeeded at blocking more attempted scam emails from entering their systems. If the malicious actors had spaced out their attacks and not gotten eager, the damage could have been worse for the organization.