Blog
/

Email

Network

/
December 4, 2024

Phishing attacks surge over 600% in the buildup to Black Friday

Default blog imageDefault blog imageDefault blog imageDefault blog imageDefault blog imageDefault blog image
04
Dec 2024
Black Friday and Cyber Monday are prime targets for cyber-attacks, as consumer spending rises and threat actors flock to take advantage. Darktrace analysis reveals a surge in retail cyber scams at the opening of the peak 2024 shopping period, and the top brands that scammers love to impersonate. Plus, don’t forget to check out our top tips for holiday-proofing your SOC before you clock off for the festive season.

Defenders are accustomed now to an uptick in cyber-attacks around the holiday period. The festive shopping season creates ideal conditions for cybercriminals. Consumers are inundated with time-sensitive deals, while retailers handle record-breaking transaction volumes at speed. This environment makes it harder than ever to identify suspicious activity.

An investigation conducted by Darktrace’s global analyst team revealed that Christmas-themed phishing attacks leapt 327%1 around the world and Black Friday and Cyber Monday themed phishing attacks soared to 692% last week compared to the beginning of November (4th - 9th November)2, as threat actors seek to take advantage of the busy holiday shopping period.

The United States retail sector saw the most marked increase in threat actors crafting convincing emails purporting to be from well-known brands, mimicking promotional emails. Attacks designed to look like they came from major brands including Walmart – which was easily the most mimicked US brand – Macy’s, Target, Old Navy, and Best Buy3 increased by more than 2000% during peak shopping periods.

Darktrace analysis also highlighted a redistribution of scammers’ resources to take advantage of the festive shopping season, moving from targeting businesses to consumers. The impersonation of major consumer brands, dominated by Amazon and PayPal4, increased by 92% globally between analyzed periods, while the spoofing of workplace-focused brands, like Adobe, Zoom and LinkedIn, decreased by 9%.

Major retail brands invest heavily in safeguarding themselves and their customers from scams and cyberattacks, particularly during the holiday season. However, phishing and website spoofing occur outside the retailers' legitimate infrastructure and security controls, making it difficult to catch and prevent every instance due to their sheer volume. While advancements like AI are helping security teams narrow the gap, brand impersonation remains a persistent challenge.

Multiple attack methods exploit trust during holiday rush

Darktrace’s findings demonstrate some of the most common brand spoofing strategies used by attackers during the holiday season:

Domain spoofing, which sees attackers create near perfect replicas of retail websites, complete with lookalike domain names and branding, to trick consumers into handing over personal and payment details.  

Brand spoofing, where attackers send a phishing email designed to look like a favorite retailer, enticing their target to click a link for a discount, when in fact the link downloads malware to their device.  

Safelink smuggling, which involves an attacker intentionally getting their malicious payload rewritten by a security solution’s Safelink capability to then propagate the rewritten URL to others. This not only evades detection but also undermines trust in email security tools. Darktrace observed over 300,000 cases of Safelinks being included in unexpected and suspicious contexts over a period of 3 months.

Multi-stage attacks which combine these tactics into a single attack: brand spoofing emails lead unsuspecting shoppers directly to domain spoofed websites that harvest login or payment details, creating a seamless deception that hands personal and financial data directly to attackers. This coordinated approach exploits the chaos of holiday sales, when shoppers are primed to expect high volumes of retail emails and website traffic promoting significant savings.

A spike in cyber-criminal activity which extends beyond email

While email often serves as the front door to an organization and the initial avenue of attack, Darktrace frequently observes a surge in cyber-attacks during public holidays5. These “off-peak” attacks exploit common organizational practices and human vulnerabilities with greater ease.

When staff numbers are reduced, and employees mentally and physically disconnect from work, the speed of detection and response has the potential to slow. This creates opportunities for threat actors to infiltrate undetected. Without real-time autonomous systems in place, such attacks can have a far more severe impact on an organization’s ability to respond and recover effectively.

Ransomware is among the most common threats targeting organizations after hours. In 76% of cases, the encryption process begins during off-hours or on weekends6. For instance, Darktrace identified a ransomware attack launched in the early hours of Christmas Day on a client’s network, taking advantage of the period when most employees were offline.

Festive cheer: giving your SOC team the break they deserve

Staff burnout is increasingly top of mind, with 74% of cybersecurity leaders reporting that they’ve had employees resign due to stress7. And the numbers stack up – almost 60% of security analysts report feeling burnt out, and many are choosing to leave their jobs and even security altogether.8

At a human level, the holiday season should be a time of relaxation and merriment rather than anxiety. For SOC leaders, giving teams time to prioritize recharging during the holidays is crucial for sustaining long-term resilience and productivity, balanced with the importance of maintaining rigorous defenses with a reduced workforce.  

So… how can cybersecurity leaders ensure peace of mind during the holidays?

Step 1: Cover yourself from every angle. It’s no longer enough for your email solution to only catch known threats. Security leaders need to invest in multi-layered email defenses that can combat novel and advanced attacks – such as the multi-stage brand personation attacks that lead shoppers to domain-spoofed websites.  

Darktrace / EMAIL – the fastest growing email security solution – has been proven to detect up to 56% more threats than other email solutions.9  It is uniquely capable of catching novel attacks on the first encounter, rather than waiting the 13 days it takes for other solutions to take action10 – by which time your decorations might be coming down, along with your business.

Step 2: Avoid an overwhelming deluge of alerts raining (or snowing) down on your L1 SOC analysts. Lining up people to manage the grunt work over the holidays is an easy pattern to fall into, but consider technology that can automate that initial triage. For example, Darktrace’s Cyber AI Analyst automatically investigates every alert detected by Darktrace’s core real-time detection engine. It does an additional layer of AI analysis – establishing whether an alert is unusual but benign, or part of a more serious security incident. Rather than looking at hundreds of alerts, your team is presented with just a handful of overall incidents. They can use that new free time to do more strategic work, or take some much-needed time off.

Step 3: Make sure someone – or something – is keeping guard in those super off-peak hours. Enter Autonomous Response. Because it knows what normal looks like for your business it can take action to stop and contain only the unusual and threatening activity. Even if it doesn’t eliminate the threat entirely, it can buy your security team time and space, allowing them to enjoy their holiday in peace.

With Black Friday over and the festive shopping period looming, businesses should act now to protect their brand and ensure they have the cybersecurity measures are in place to enjoy the gift of a stress-free holiday season.  

Interested in how AI-driven email security can protect your organization? Check out the product hub to learn more. Or watch the demo video to see Darktrace / EMAIL in action.

[1] Based on analysis of 626 customer deployments and attempted phishing emails mentioning Christmas that were detected by Darktrace / EMAIL.

[1] Emails in the analysis mentioning ‘Black Friday’ or ‘Cyber Monday’.

[1] Walmart, Target, Best Buy, Macy's, Old Navy, 1800-Flowers

[1] Amazon, eBay, Netflix, Alibaba, Paypal, Apple

[1] Oracle, Zoom, Adobe, Microsoft Exchange, Microsoft Outlook, Microsoft Teams, Slack, WeTransfer, Docusign, Sharepoint, Linkedin, Dropbox

Inside the SOC
Darktrace cyber analysts are world-class experts in threat intelligence, threat hunting and incident response, and provide 24/7 SOC support to thousands of Darktrace customers around the globe. Inside the SOC is exclusively authored by these experts, providing analysis of cyber incidents and threat trends, based on real-world experience in the field.
Author
Nathaniel Jones
Director of Strategic Threat and Engagement

Nathaniel Jones is the VP of Threat Research at Darktrace, where he leads initiatives in strategic accounts, customer engagement, and industry collaboration to enhance AI-driven cybersecurity solutions. Drawing on his extensive background in both government and private sector cybersecurity, including six years at the U.S. Cybersecurity and Infrastructure Security Agency (CISA), Nathaniel brings a global perspective to threat analysis and defense strategies. Notably, he served as CISA's operational liaison to the UK's Government Communications Headquarters (GCHQ), an experience that particularly resonates in his UK-focused work. His expertise spans threat hunting, cyber intelligence, and incident response across multiple countries. At Darktrace, Nathaniel applies this diverse experience to drive product innovation and improve real-time threat detection and response capabilities, addressing the evolving challenges in the cybersecurity landscape. He holds a Master's Degree focusing on international management and security policy, and is a Certified Information Security Manager (CISM) and Certified Ethical Hacker (CEH).

Book a 1-1 meeting with one of our experts
Share this article

More in this series

No items found.

Blog

/

November 28, 2024

/

Cloud

Cloud security: addressing common CISO challenges with advanced solutions

Default blog imageDefault blog image

Cloud adoption is a cornerstone of modern business with its unmatched potential for scalability, cost efficiency, flexibility, and net-zero targets around sustainability. However, as organizations migrate more workloads, applications, and sensitive data to the cloud it introduces more complex challenges for CISO’s. Let’s dive into the most pressing issues keeping them up at night—and how Darktrace / CLOUD provides a solution for each.

1. Misconfigurations: The Silent Saboteur

Misconfigurations remain the leading cause of cloud-based data breaches. In 2023 alone over 80%  of data breaches involved data stored in the cloud.1  Think open storage buckets or overly permissive permissions; seemingly minor errors that are easily missed and can snowball into major disasters. The fallout of breaches can be costly—both financially and reputationally.

How Darktrace / CLOUD Helps:

Darktrace / CLOUD continuously monitors your cloud asset configurations, learning your environment and using these insights to flag potential misconfigurations. New scans are triggered when changes take place, then grouped and prioritised intelligently, giving you an evolving and prioritised view of vulnerabilities, best practice and mitigation strategies.

2. Hybrid Environments: The Migration Maze

Many organizations are migrating to the cloud, but hybrid setups (where workloads span both on-premises and cloud environments) create unique challenges and visibility gaps which significantly increase complexity. More traditional and most cloud native security tooling struggles to provide adequate monitoring for these setups.

How Darktrace / CLOUD Helps:

Provides the ability to monitor runtime activity for both on-premises and cloud workloads within the same user interface. By leveraging the right AI solution across this diverse data set, we understand the behaviour of your on-premises workloads and how they interact with cloud systems, spotting unusual connectivity or data flow activity during and after the migration process.

This unified visibility enables proactive detection of anomalies, ensures seamless monitoring across hybrid environments, and provides actionable insights to mitigate risks during and after the migration process.

3. Securing Productivity Suites: The Last Mile

Cloud productivity suites like Microsoft 365 (M365) are essential for modern businesses and are often the first step for an organization on a journey to Infrastructure as a Service (IaaS) or Platform as a Service (PaaS) use cases. They also represent a prime target for attackers. Consider a scenario where an attacker gains access to an M365 account, and proceeds to; access sensitive emails, downloading files from SharePoint, and impersonating the user to send phishing emails to internal employees and external partners. Without a system to detect these behaviours, the attack may go unnoticed until significant damage is done.

How Darktrace helps:

Darktrace’s Active AI platform integrates with M365 and establishes an understanding of normal business activity, enabling the detection of abnormalities across its suite including Email, SharePoint and Teams. By identifying subtle deviations in behaviour, such as:

   •    Unusual file accesses

   •    Anomalous login attempts from unexpected locations or devices.

   •    Suspicious email forwarding rules created by compromised accounts.

Darktrace’s Autonomous Response can act precisely to block malicious actions, by disabling compromised accounts and containing threats before they escalate. Precise actions also ensure that critical business operations are maintained even when a response is triggered.  

4. Agent Fatigue: The Visibility Struggle

To secure cloud environments, visibility is critical. If you don’t know what’s there, how can you secure it? Many solutions require agents to be deployed on every server, workload, and endpoint. But managing and deploying agents across sprawling hybrid environments can be both complex and time-consuming when following change controls, and especially as cloud resources scale dynamically.

How Darktrace / CLOUD Helps:

Darktrace reduces or eliminates the need for widespread agent deployment. Its agentless by default, integrating directly with cloud environments and providing instant visibility without the operational headache. Darktrace ensures coverage with minimal friction. By intelligently graphing the relationships between assets and logically grouping your deployed Cloud resources, you are equipped with real-time visibility to quickly understand and protect your environment.

So why Darktrace / CLOUD?

Darktrace’s Self-Learning AI redefines cloud security by adapting to your unique environment, detecting threats as they emerge, and responding in real-time. From spotting misconfigurations to protecting productivity suites and securing hybrid environments. Darktrace / CLOUD simplifies cloud security challenges without adding operational burdens.

From Chaos to Clarity

Cloud security doesn’t have to be a game of endless whack-a-mole. With Darktrace / CLOUD, CISOs can achieve the visibility, control, and proactive protection they need to navigate today’s complex cloud ecosystems confidently.

[1] https://hbr.org/2024/02/why-data-breaches-spiked-in-2023

Continue reading
About the author
Adam Stevens
Director of Product, Cloud Security

Blog

/

November 27, 2024

/

Inside the SOC

Behind the veil: Darktrace's detection of VPN exploitation in SaaS environments

Default blog imageDefault blog image

Introduction

In today’s digital landscape, Software-as-a-Service (SaaS) platforms have become indispensable for businesses, offering unparalleled flexibly, scalability, and accessibly across locations. However, this convenience comes with a significant caveat - an expanded attack surface that cyber criminals are increasingly exploiting. In 2023, 96.7% of organizations reported security incidents involving at least one SaaS application [1].

Virtual private networks (VPNs) play a crucial role in SaaS security, acting as gateways for secure remote access and safeguarding sensitive data and systems when properly configured. However, vulnerabilities in VPNs can create openings for attacks to exploit, allowing them to infiltrate SaaS environments, compromise data, and disrupt business operations. Notably, in early 2024, the Darktrace Threat Research team investigated the exploitation of zero-day vulnerabilities in Ivanti Connect Secure VPNs, which would allow threat actors to gain access to sensitive systems and execute remote code.

More recently, in August, Darktrace identified a SaaS compromise where a threat actor logged into a customer’s VPN from an unusual IP address, following an initial email compromise. The attacker then used a separate VPN to create a new email rule designed to obfuscate the phishing campaign they would later launch.

Attack Overview

The initial attack vector in this case appeared to be through the customer’s email environment. A trusted external contact received a malicious email from another mutual contact who had been compromised and forwarded it to several of the organization’s employees, believing it to be legitimate. Attackers often send malicious emails from compromised accounts to their past contacts, leveraging the trust associated with familiar email addresses. In this case, that trust caused an external victim to unknowingly propagate the attack further. Unfortunately, an internal user then interacted with a malicious payload included in the reply section of the forwarded email.

Later the same day, Darktrace / IDENTITY detected unusual login attempts from the IP 5.62.57[.]7, which had never been accessed by other SaaS users before. There were two failed attempts prior to the successful logins, with the error messages “Authentication failed due to flow token expired” and “This occurred due to 'Keep me signed in' interrupt when the user was signing in.” These failed attempts indicate that the threat actor may have been attempting to gain unauthorized access using stolen credentials or exploiting session management vulnerabilities. Furthermore, there was no attempt to use multi-factor authentication (MFA) during the successful login, suggesting that the threat actor had compromised the account’s credentials.

Following this, Darktrace detected the now compromised account creating a new email rule named “.” – a telltale sign of a malicious actor attempting to hide behind an ambiguous or generic rule name.

The email rule itself was designed to archive incoming emails and mark them as read, effectively hiding them from the user’s immediate view. By moving emails to the “Archive” folder, which is not frequently checked by end users, the attacker can conceal malicious communications and avoid detection. The settings also prevent any automatic deletion of the rules or forced overrides, indicating a cautious approach to maintaining control over the mailbox without raising suspicion. This technique allows the attacker to manipulate email visibility while maintaining a façade of normality in the compromised account.

Email Rule:

  • AlwaysDeleteOutlookRulesBlob: False
  • Force: False
  • MoveToFolder: Archive
  • Name: .
  • MarkAsRead: True
  • StopProcessingRules: True

Darktrace further identified that this email rule had been created from another IP address, 95.142.124[.]42, this time located in Canada. Open-source intelligence (OSINT) sources indicated this endpoint may have been malicious [2].

Given that this new email rule was created just three minutes after the initial login from a different IP in a different country, Darktrace recognized a geographic inconsistency. By analyzing the timing and rarity of the involved IP addresses, Darktrace identified the likelihood of malicious activity rather than legitimate user behavior, prompting further investigation.

Figure 1: The compromised SaaS account making anomalous login attempts from an unusual IP address in the US, followed by the creation of a new email rule from another VPN IP in Canada.

Just one minute later, Darktrace observed the attacker sending a large number of phishing emails to both internal and external recipients.

Figure 2: The compromised SaaS user account sending a high volume of outbound emails to new recipients or containing suspicious content.

Darktrace / EMAIL detected a significant spike in inbound emails for the compromised account, likely indicating replies to phishing emails.

Figure 3: The figure demonstrates the spike in inbound emails detected for the compromised account, including phishing-related replies.

Furthermore, Darktrace identified that these phishing emails contained a malicious DocSend link. While docsend[.]com is generally recognized as a legitimate file-sharing service belonging to Dropbox, it can be vulnerable to exploitation for hosting malicious content. In this instance, the DocSend domain in question, ‘hxxps://docsend[.]com/view/h9t85su8njxtugmq’, was flagged as malicious by various OSINT vendors [3][4].

Figure 4: Phishing emails detected containing a malicious DocSend link.

In this case, Darktrace Autonomous Response was not in active mode in the customer’s environment, which allowed the compromise to escalate until their security team intervened based on Darktrace’s alerts. Had Autonomous Response been enabled during the incident, it could have quickly mitigated the threat by disabling users and inbox rules, as suggested by Darktrace as actions that could be manually applied, exhibiting unusual behavior within the customer’s SaaS environment.

Figure 5: Suggested Autonomous Response actions for this incident that required human confirmation.

Despite this, Darktrace’s Managed Threat Detection service promptly alerted the Security Operations Center (SOC) team about the compromise, allowing them to conduct a thorough investigation and inform the customer before any further damage could take place.

Conclusion

This incident highlights the role of Darktrace in enhancing cyber security through its advanced AI capabilities. By detecting the initial phishing email and tracking the threat actor's actions across the SaaS environment, Darktrace effectively identified the threat and brought it to the attention of the customer’s security team.

Darktrace’s proactive monitoring was crucial in recognizing the unusual behavior of the compromised account. Darktrace / IDENTITY detected unauthorized access attempts from rare IP addresses, revealing the attacker’s use of a VPN to hide their location.

Correlating these anomalies allowed Darktrace to prompt immediate investigation, showcasing its ability to identify malicious activities that traditional security tools might miss. By leveraging AI-driven insights, organizations can strengthen their defense posture and prevent further exploitation of compromised accounts.

Credit to Priya Thapa (Cyber Analyst), Ben Atkins (Senior Model Developer) and Ryan Traill (Analyst Content Lead)

Appendices

Real-time Detection Models

  • SaaS / Compromise / Unusual Login and New Email Rule
  • SaaS / Compromise / High Priority New Email Rule
  • SaaS / Compromise / New Email Rule and Unusual Email Activity
  • SaaS / Compromise / Unusual Login and Outbound Email Spam
  • SaaS / Compliance / Anomalous New Email Rule
  • SaaS / Compromise / Suspicious Login and Suspicious Outbound Email(s)
  • SaaS / Email Nexus / Possible Outbound Email Spam

Autonomous Response Models

  • Antigena / SaaS / Antigena Email Rule Block
  • Antigena / SaaS / Antigena Enhanced Monitoring from SaaS User Block
  • Antigena / SaaS / Antigena Suspicious SaaS Activity Block

MITRE ATT&CK Mapping

Technique Name Tactic ID Sub-Technique of

  • Cloud Accounts. DEFENSE EVASION, PERSISTENCE, PRIVILEGE ESCALATION, INITIAL ACCESS T1078.004 T1078
  • Compromise Accounts RESOURCE DEVELOPMENT T1586
  • Email Accounts RESOURCE DEVELOPMENT T1586.002 T1586
  • Internal Spearphishing LATERAL MOVEMENT T1534 -
  • Outlook Rules PERSISTENCE T1137.005 T1137
  • Phishing INITIAL ACCESS T1566 -

Indicators of Compromise (IoCs)

IoC – Type – Description

5.62.57[.]7 – Unusual Login Source

95.142.124[.]42– IP – Unusual Source for Email Rule

hxxps://docsend[.]com/view/h9t85su8njxtugmq - Domain - Phishing Link

References

[1] https://wing.security/wp-content/uploads/2024/02/2024-State-of-SaaS-Report-Wing-Security.pdf

[2] https://www.virustotal.com/gui/ip-address/95.142.124.42

[3] https://urlscan.io/result/0caf3eee-9275-4cda-a28f-6d3c6c3c1039/

[4] https://www.virustotal.com/gui/url/8631f8004ee000b3f74461e5060e6972759c8d38ea8c359d85da9014101daddb

Continue reading
About the author
Priya Thapa
Cyber Analyst
Your data. Our AI.
Elevate your network security with Darktrace AI