Malicious HTML Attachments – Olesia Klevchuk, Barracuda Networks
Olesia Klevchuk, product marketing director for Barracuda Networks, explains how HTML attachments are becoming much more malicious.
Transcript
This is texturing TV. Hey guys. Thanks for the throw.
We're here with the Alicia Club Chuck who's a product marketing director for Barracuda networks, and we're talking about HTML attachments and security these days Alicia. Welcome the show. Hi, thanks for having me.
You guys just put out a report that says that for the most part it's HTML attachments that are the most malicious these days folks tend to think of PDFs and all kinds of other stuff. So is there a shift going on here? And if so, what's driving that Well, you know, I think HTML attachments has always been a big problem.
It's just that this problem is growing over time because they're so easy for hackers to use to trick users into you know, entering their credentials into into fishing sides. It's much harder to do so with PDFs or Word documents HTML attachment is just lend themselves so well to to different hacks. Is there some way to discover these attachments that people should be using or is it really just a matter of training end users not to go click on them or maybe a little bit above?
You know, whether it's really a combination of both like you you do want your email security to look out for HTML attachments. Not every everyone that offers that but most do today. So you do want to to look for those HTML attachments.
You don't do the same time want to just block all of them because there are teams within each organization their individuals within each organizations that may expect to receive HTML attachments but not everybody. So you do want to look for for them and I would say, you know about research found one and five of those attachments are malicious. So if you get one you want to treat all of them suspiciously compared to PDFs words or any other one.
So in the same way, you would probably treat executables a lot of organizations just block executables, but that is not always the best strategy which HTML and another way of looking at for HTML attachments. It's not just Looking at that attachments themselves, but you really want to take into account everything else about the email. Where's this email is coming from who is sending this maybe even contents of the email message as well and look for other signals that may suggest that the attachment is malicious.
The biggest challenge with HTML attachments is that that attachments themselves most of a time and not malicious. So if you scan for some malicious code and malicious payload, you'll find nothing because all they do is just redirect someplace else that may have malicious intent behind it. You mentioned training training is of course a really really big part of that training uses to be suspicious of HTML attachments designers web developers.
They probably share HTML attachments between themselves. But if you're in sales department, how many times do you receive that make sure that they aware that this might be Problem put a make sure. It's part of your ongoing security awareness training and that you train them not just to be suspicious of links but also pay attention of the type of attachments they get do you think that the people who are putting out these fake attachments are getting better at this they're starting to look more realistic and you know the days when you could tell it was, you know from a Nigerian prince or whatever over and that these things are kind of becoming more sophisticated and people are getting more easily full.
Yeah, for sure. We see that with pretty much any attack any threat that hackers are using they're getting Better they're using social engineering tactics to really trick users into believing them. What they're getting is is the real thing and perfectly legitimate email and when it comes to this particular type of an attack the One one of the reasons why is just it can be so effective and why it's so many of them are malicious is because you know you open HTML attachments and very often.
There's just loads on your local machine, right? Like it's not hosted on a public internet therefore all of the usual tactics that organizations use to prevent this attacks such as link protections and I just ineffective because they're not hosted on the public website. But once you start entering your credentials, you know, those are actually going to the hackers.
So it's it's a pretty clever way. That's it. That's involve a little bit more of an effort and just typing an email saying I have three million dollars 7300 and I'll wire it to you that it requires a lot more effort to creating those attachments making sure that it's all set up getting through all of the systems but the payout is so much bigger as well.
Right? All right, so that Lottery that I allegedly won in some country that I've never been to I should be suspicious of right? All right.
What is your thought process about can we ever maybe start to use machine learning algorithms and maybe AI in the future to kind of identify this stuff because to your point, I can't really scan it. But are there other giveaways that I can go look for? Yeah, you absolutely right because you you can definitely use, you know, you you definitely have a technology to scan the attachments right to look for malicious payloads within that and see how it yes.
There is nothing really there's no malicious payload with attachment is just read that racks then you want to For other things in addition to those redirects and in addition to being able to scan where it's getting redirected to so machine learning can really help here to look for other clues that may um kind of identify a malicious email. So looking for where's the email is coming from? Is this the kind of email if you've got them before have you ever received an HTML attachment?
Is there a language within an email that might be suspicious a suspicious request in an email address. There's never been associated with an individual's name. That is the email is coming from so all of those things, you know is Could be a sign of a malicious email, but it's really difficult to.
Create a set of rules and policies that are able to identify all of this different variations and things that are kind of outside of the norm and that's where machine learning and AI can really come in and help and to create kind of statistical models around communication patterns and any deviation from those norms and those statistical models. They can flag as malicious. So you want to have a security that has a combination of both really, you know, traditional scanning technology as well as AI for more targeted threats, and that's the harder to identify.
Should we be changing our credentials more? Because at least from my perspective someone will take your credentials through that HTML page, but they may not use it immediately A lot of times they'll log in kind of hang around they might insert some malware. It might be months though before you actually feel the pain of an attack.
There was created because of their ability to grab your credentials. So, you know, is this a lesson in the fact that we need to be more aggressive about managing credentials and passwords because you never know when something is gonna Return to bite you later. But to you at the time you didn't think anything of it.
Yeah, I think changing credentials changing your passwords could be. Could be a good practice, but it's not. It's not the best one out there, you know, there are other practices that I think will make a much bigger impact than just changing your credentials and the regular basis because you know, all of our personal information is out there every other week we get we see the news about another data breach and another League just today or something about data breach of Marriott Hotels.
A lot of credentials got stolen there and a lot of individuals actually reuse the password. So, you know, if you are using the same password as with your you know with your personal accounts hackers can go and and use that so there is probably personal information about it somewhere in the dark web as well. The way organizations can protect credentials.
So their employees is really through a couple of different ways. One of the best one is a multi-factor authentication and the organization should put that in place first and foremost that is going to be way more effective than having them. Change passwords every two to three months and you know people just start reusing passwords because they'll forget them but multifact authentication can really really help but it's again it's not a silver bullet.
It can be circumvented by hackers. They have ways of getting around it. So training is a big part as well.
So making sure that they individuals not just don't click on where they shouldn't be clicking but are are also reporting in suspicious activity within their accounts and that they think are odd emails that they receiving or sending that they were not expecting and lastly organizations should really monitor for any suspicious activities are within their accounts in case those credentials got compromised. So other emails being said that all times other Emails coming from locations that you don't have you use this logging in from there all of a sudden mass emails going out other suspicious and malicious emails going out today suspicious rules changes within their account, you know, there's so many signs that could tell that there is a hacker or somebody inside an organization and using has already compromised an account. So if organizations have all of those things in place You know, you can't ever prevent credential theft 100% of the time but you can really reduce the risk associated with that or risk of that happening within the organization.
So you've been at this a little while once the one thing that you see organizations doing over and over again, that just makes you shake your head and wonder how come we keep doing the same silly thing over and over again. Yeah, so I think probably one of the biggest things is just Treating everything thinking the spam is your biggest problem. A lot of organizations really focus on high volume attacks and they say, you know, what if I block 1995% of their attacks which are spam or known malware.
I'm good. I don't need anything else the rest, you know, the risk is too low for me. Nobody's gonna click it.
Maybe I'll just tell my users to be careful and there isn't you can't you can't do that because that that long tail that last five two percent of the attacks are the ones that you actually want to be really really focused on because it's like you said everybody knows the Nigerian prince scam. If you get an email that has a spelling mistakes from where you never got before the chances will be falling for that has so much low, especially in the business environment. Then a carefully Engineers social engineering attacks.
They personally your boss who is asking you to give them a call because they have an urgent favor to ask that's a much more clever attack, but it's also so much harder to detect and a lot of the time organizations do need to make additional Investments to make protection against those attacks. But those are their attacks the ones they get through. They're the ones that have a much higher success rate compared to spam or any other ones.
All right. Well, there's a felony Murphy who wrote a law about that and basically, you know, if you can't happen it's likely to happen. So you might as well get prepared for it now Alicia.
Thanks for being on the show. Thank you. All right back to you guys in the studio.