China, US and Russia are frequent targets for Covid-19 related phishing attacks


China, the US and Russia have been the frequent targets for Covid-19 related phishing attacks, followed by Japan, Latin America, Europe and other parts of Asia Pacific due to remote working, Microsoft security expert said.
Ann Johnson, Corporate Vice-President for Cybersecurity Solutions Group at Microsoft, said that they are seeing a significant increase in Covid-19 related phishing attacks and are blocking about 24,000 bad emails per day and, at one point, have observed 116 phishing campaigns related to the pandemic.
“We have seen about 2,300 unique HTML attachments themed as Covid financial compensation in one campaign alone. We also have blocked 18,000 Covid themed URLs and IP addresses on a single day. We are not seeing an overall increase in phishing attacks but only related to Covid-19. Phishing attacks have changed in dimension to be more Covid-19 related,” she said.
Accordion to Barracuda researchers, they have detected 467,825 spear-phishing email attacks between March 1 and March 23, and 9,116 of those detections were related to Covid-19, representing about 2% of attacks.
In comparison, a total of 1,188 coronavirus-related email attacks were detected in February, and just 137 were detected in January.
Organisations around the world are adapting to remote work options, supporting workers to have access to data, information and networks.
Johnson said that the work-from-home policy has increased the temptation for bad actors and security teams must look urgently at new scenarios and new threat actors as the organisations have now become distributed overnight and with less time to make detailed plans or run pilots.
“We have seen an instant increase in attacks whenever there is a Covid hotspot globally and wane off slowly when the next hotspot arises,” she said.
Moreover, she said that threats actors are not going to slow down and are going to advantage of global disruptions in businesses and increase the attacks.
The work-from-home strategy ranges from online communication tools such as Microsoft Teams or Windows virtual desktops, she said and added that these have security and productivity implications in place.
“We have used split tunnelling for VPNs so that internet-based assets can access securely without VPNs and with multi-factor authentication to avoid phishing attacks so that companies can feel very comfortable in accessing Teams and continue to have virtual meetings without having to depend on VPN bandwidth. The other trend we are seeing is that companies are moving to a virtual desktop environment,” she said.
Well prepared to defend attacks
However, Johnson said that an increase, which happened during the start of the year in state-sponsored attacks or advanced persistent threats (APTs), is normalising now for the past to three days.
“We have a lot of technologies to help protect customers and block attacks through machine learning by using 8 trillion data threat signals per day to understand what is good and what is bad.
“We have our exchange online protection that does email filtering, in addition to Microsoft Defender ATP at the endpoints looking for known bad URLs,” Johnson said.
One of the other technologies, she said that Microsoft is trying hard to implement on the customers is the Azure active directory with traditional access.
“When you are working from home, you want to have the full view of the user behaviour, device behaviour, application behaviour and network behaviour. We continue to build proactive protections against Covid-related attacks, either manually or by using machine learning,” she said.
Bad actors are preying on the physiology of the end-users and, at the same time, she said that the end-users are extremely stressed about the health of their families, loss of lives they are seeing and hearing, schooling their children at home and work from home.
Johnson said raising awareness is the key and urged home workers not to click on any unauthenticated links and enable multi-factor authentication 100% of the time.
“Multi-factor authentication is one way to block the harm during the crises,” she added.
China, the US and Russia have been the frequent targets for Covid-19 related phishing attacks, followed by Japan, Latin America, Europe and other parts of Asia Pacific due to remote working, Microsoft security expert said. Ann Johnson, Corporate Vice-President for Cybersecurity Solutions Group at Microsoft, said that they are seeing…
Recent Posts
- The GSA is shutting down its EV chargers, calling them ‘not mission critical’
- Lenovo is going all out with yet another funky laptop design: this time, it’s a business notebook with a foldable OLED screen
- Elon Musk’s first month of destroying America will cost us decades
- Fortnite’s new season leans heavily on heist mechanics
- I installed iOS 18.4 dev beta and the big Siri intelligence update is nowhere to be found
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010