Evasion Techniques: User-Agent Blocking

Evasion Techniques: User-Agent Blocking

Recently we highlighted one of the most common evasion techniques employed by threat actors in order to keep a phishing site online: geoblocking, or blocking by location. However, many other techniques exist, ...
How Threat Actors are Abusing Coronavirus Uncertainty

How Threat Actors are Abusing Coronavirus Uncertainty

By this time, most everyone in the world has heard about COVID-19, a global outbreak that is commonly referred to as the Coronavirus. With growing fear and a lack of information, the ...
Phishing Campaign Uses Malicious Office 365 App

Phishing Campaign Uses Malicious Office 365 App

Most phishing campaigns use social engineering and brand impersonation to attempt to take over accounts and trick the victim into divulging their credentials. PhishLabs has uncovered a previously unseen tactic by attackers ...
Unique Countermeasures in Active Phishing Campaign Avoids Security Tools

Unique Countermeasures in Active Phishing Campaign Avoids Security Tools

PhishLabs’ Email Incident Response analysts recently identified a phishing campaign leveraging novel tactics in the ongoing war between threat actors and security teams. In addition to presenting a unique twist on a ...
Active Office 365 Phishing Campaign Targeting Admin Credentials

Active Office 365 Phishing Campaign Targeting Admin Credentials

PhishLabs has detected attempts to compromise Microsoft Office 365 administrator accounts as part of a broad phishing campaign. In the campaign, the threat actor(s) delivered a phishing lure that impersonated Microsoft and ...
The Vast Social Media Landscape for Phishing Threats

The Vast Social Media Landscape for Phishing Threats

On a daily basis, around 42% of the global population, or 3.2 billion people, uses some form of social media. Of that number, people spend a daily average of 2.2 hours on ...
BEC Attacks: How CEOs and Executives are Put at Risk

BEC Attacks: How CEOs and Executives are Put at Risk

Business Email Compromise (BEC) attacks are the most costly and effective forms of phishing. In most cases, these attacks use highly research social engineering to go after the top brass in a ...
PhishLabs Enhances Email Incident Response Service

PhishLabs Enhances Email Incident Response Service

Today we are excited to announce the general availability of our enhanced Email Incident Response service. Email Incident Response detects, prevents, and automatically responds to threats that bypass email security technology ...