Attackers turn to vishing: 550 percent increase seen in vishing attacks
- Published: Thursday, 26 May 2022 07:18
Vishing (voice phishing) cases have increased almost 550 percent over the twelve month period Q1 2021 to Q1 2022, according to the latest Quarterly Threat Trends & Intelligence Report from Agari and PhishLabs.
In Q1 2022, Agari and PhishLabs detected and mitigated hundreds of thousands of phishing, social media, email, and dark web threats targeting a broad range of enterprises and brands. The report provides an analysis of the latest findings and insights into key trends shaping the threat landscape.
According to the findings, vishing attacks have overtaken business email compromise (BEC) as the second most reported response-based email threat since Q3 2021. By the end of the year, more than one in four of every reported response-based threat was a vishing attack, and this makeup continued through Q1 2022.
“Hybrid vishing campaigns continue to generate stunning numbers, representing 26.1 percent of total share in volume so far in 2022,” said John LaCour, principal strategist at HelpSystems (Agari and PhishLabs are both part of the HelpSystems cybersecurity portfolio). “We are seeing an increase in threat actors moving away from standard voice phishing campaigns to initiating multi-stage malicious email attacks. In these campaigns, actors use a callback number within the body of the email as a lure, then rely on social engineering and impersonation to trick the victim into calling and interacting with a fake representative.”
Additional key findings include:
- Social media impersonation attacks are on the rise. Since Q2 2021, the volume of brand impersonations increased 339 percent and executive impersonations 273 percent. According to the findings, brands prove to be convenient targets for threat actors, especially when associated with retail counterfeit operations. However, for some unique attacks, executive accounts are preyed on to make the spoofs seem more realistic.
- Credential theft email scams continue to be the most common email threat type reported by employees, contributing to nearly 59 percent of all threat types encountered. Credential theft reports increased 6.9 percent in volume from Q4 2021.
- The malware landscape continues to be ever changing. Qbot was once again the payload of choice for threat actors attempting ransomware attacks, but Emotet re-emerged in Q1 and was the second leading payload.
- While nearly half of all phishing sites rely on a free tool or service for staging, Q1 2022 was the first quarter in five consecutive quarters where paid or compromised services (52 percent) outnumbered free solutions for the use of staging phishing sites.