Email Incident Response
Evasion Techniques: User-Agent Blocking
Recently we highlighted one of the most common evasion techniques employed by threat actors in order to keep a phishing site online: geoblocking, or blocking by location. However, many other techniques exist, ...
How Threat Actors are Abusing Coronavirus Uncertainty
By this time, most everyone in the world has heard about COVID-19, a global outbreak that is commonly referred to as the Coronavirus. With growing fear and a lack of information, the ...
Phishing Campaign Uses Malicious Office 365 App
Most phishing campaigns use social engineering and brand impersonation to attempt to take over accounts and trick the victim into divulging their credentials. PhishLabs has uncovered a previously unseen tactic by attackers ...
Unique Countermeasures in Active Phishing Campaign Avoids Security Tools
PhishLabs’ Email Incident Response analysts recently identified a phishing campaign leveraging novel tactics in the ongoing war between threat actors and security teams. In addition to presenting a unique twist on a ...
Active Office 365 Phishing Campaign Targeting Admin Credentials
PhishLabs has detected attempts to compromise Microsoft Office 365 administrator accounts as part of a broad phishing campaign. In the campaign, the threat actor(s) delivered a phishing lure that impersonated Microsoft and ...
The Vast Social Media Landscape for Phishing Threats
On a daily basis, around 42% of the global population, or 3.2 billion people, uses some form of social media. Of that number, people spend a daily average of 2.2 hours on ...
BEC Attacks: How CEOs and Executives are Put at Risk
Business Email Compromise (BEC) attacks are the most costly and effective forms of phishing. In most cases, these attacks use highly research social engineering to go after the top brass in a ...
PhishLabs Enhances Email Incident Response Service
Today we are excited to announce the general availability of our enhanced Email Incident Response service. Email Incident Response detects, prevents, and automatically responds to threats that bypass email security technology ...

