April Threat Report

April Threat Report

The TwinWave Security research team’s April threat report identified some interesting trends and changes in attacker TTPs.

Along with credential phishing and malware trends, some highlights from the report include:

Credential Phishing

  • abuse of new free web services like chirpy.io and others
  • increased use of distributed overlay/p2p networks to host phishing pages
  • growing use of anti-bot services fronting phishing pages
  • write up on Team CC and how they use fake Cloudflare pages

Malware

  • greater adoption of abusing “findstr” + webdav for payload downloads
  • experimentation by Emotet, Qakbot, etc. on alternatives to macros

To receive a copy of the full report you can register here or DM @MikeHorn.

Tom Gillis

SVP/GM Security, Data Center, Internet & Cloud Infrastructure at Cisco

2 年

Great report. I like the depth that twinwave produces!

要查看或添加评论,请登录

TwinWave Security (acquired by Splunk)的更多文章

社区洞察

其他会员也浏览了