Unmasking Advanced Phishing Threats with Fortra’s Josh Taylor
Josh Taylor, lead security analyst for Fortra, explains how more sophisticated social engineering tactics and techniques are being used to launch more lethal phishing attacks.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Josh Taylor, who's the lead security analyst for Fort, and we're talking about how social engineering attacks are evolving 'cause well, the bad guys.
Getting a little more clever these days. Hey Josh, welcome to the show. Hi Mike.
Thanks for having me. You've been following this space for a while. What are you seeing?
How are these tactics changing? Because we've certainly come a long way since, you know, those Nigerian princes were sending us faxes, right? We sure have.
Um, what we're seeing is an uptick, especially in the last, I would say six months or so with, uh, these particular types of attacks. Uh, some of that is just the fact that the person is always the, or the user is always the weakest link in the security chain. So you're seeing attackers still focused on, on focusing their efforts there, but you're also seeing the iteration of these attacks going through multiple rounds of ai.
And so they are becoming better at crafting these attacks to trick users. So what do they look like? Do they have patterns or are they so good?
We can't even distinguish them anymore? They're definitely getting better. There are definitely some patterns though that are out there.
Um, some of the more common ones are things like capcha attacks that they're doing that look like they're trying to verify whether or not you're a human. Uh, we're seeing some of those particularly lately. And then we're still seeing ones that are presenting themselves as things like security updates and other things that, that represent authority on, on your system that you might be used to seeing already.
And they're really making them look a lot like those types of, of fields when they're presenting them to users. Will you start to hear a little bit about phrases like scam yourself or are we basically being fooled into fooling ourselves? Pretty much.
That is the, that is the whole idea behind these is that the attacker plays on the user to actually participate in the attack themselves. And so therefore they are kind, the user is kind of scamming themselves instead of everything having to be done by the attacker, the user plays a part in these, in these types of attacks. I'm assuming that's unwillingly, but part of the issue, I think is that the end user doesn't realize that they are a means to another end, and so they're just happily doing whatever it is they're doing.
And then I'm assuming the cyber criminals are then using that access to move laterally into the organization and cause all kinds of havoc? Definitely. It's a point of entry for them.
And from there they're able to do things like reconnaissance or establish, uh, persistence on either the device or in the network. And from there do things like download other tools or set up command and control and further their attacks into, into corporations or just on your personal device. Is it getting harder for us to distinguish that?
And there are these attacks essentially seems like they're slow moving and lasting maybe a lot longer? I think it is getting harder to attack. There's, if you look at things like phishing emails, we now have a lot of spam filters and other types of filters that scan for this type of activity.
But when a lot of these things are being presented to the user, it's being done through things like their web browser, it's, it's not as easy to detect on the front end. What we're seeing is a lot of secondary detection. So the actual first attack and the scam yourself portion will get through to a user because there's not very good filters for detecting that.
But then when we see secondary things like a PowerShell script execute or something like that, that's when we're able to, to notice the activity and, uh, start an investigation. So do you think that these attacks are more lethal than they used to be back in the day? I mean, um, are they deeper into our organizations and are the dollar values and the impacts and for that matter, the, uh, entire scope of the breach getting larger?
That's a good question. Uh, um, I think it really depends on how high up typically the user that they're able to compromise. Um, so it's, it's different every time, but of course as the attacks get more sophisticated, the attackers will feel more emboldened about reaching out to higher level people, maybe executives, uh, your C-suite people.
And if, and if they're fooled, then of course the attacks can be, can have a, a very dramatic impact on the organization. Will maybe AI save us from ourselves one day soon or is it already, I I think it's gonna play a role. I think attackers are using AI to craft these attacks and I truly believe that in the future we will leverage that as defenders as well to scan things like behaviors and, and what is going on, uh, at user endpoints and look for these types of attacks.
Is it your sense then that we're kinda, uh, involved in some sort of AI arms race here then? I think that most organizations will wind up utilizing this in the future against attacks? So yes, I, I would say that it is, that is a term I would use.
It is it is an arms race. Attackers are going to leverage this, so then defenders must as well, and, and we just need to be ahead of, of ahead of them at those, at those steps. The part about all this that, uh, your average business executive is gonna, uh, shake their head about is do I need another full round of investments in cybersecurity platforms to combat these threats?
Or will the ones that I have kind of evolve to combat them? 'cause the former implies, uh, forklift upgrades of some type and the latter sounds more like, uh, features are gonna be added over top Right. And I think those things are all great down the road potentially, um, for users in organizations and, and people in those, you know, decision making spots right now.
I would say that a lot of this just starts with having a culture of healthy skepticism at your organization, taking a second look at, uh, workflows and, and what's going on with them and really ingraining that with users. And then to take it even a step further, which doesn't have to be something that you know, you're investing a lot of money in, is just making simple checklists for critical tasks. So if you have a critical task, you can do things like create these checklists.
It's, it happens a lot in engineering. And then when something is outside of those checklists, you're able to have somebody, you know, raise that skepticism, raise their hand, and, and ask what's going on there. And that can a lot of times detect a lot of these things that are going on in these organizations.
And then also reach reaching out to users and letting them know that, you know, if they're going to be doing things like surfing the internet or going to sites maybe that, you know, they should not be and things like that, that just shouldn't be done up there on their corporate device. As much fun as that is to enforce, Are we getting better at collaborating with each other to combat these threats? I mean, back in the day when there were bandits in the desert, we had caravans and the reason we had caravans was for mutual defense.
So, um, does that same concept starting to apply here and are people getting it? I certainly think we're getting better at it. It needs to be a continued effort though for sure.
We're always trying to stay one step ahead and that requires a lot of collaboration and forward thinking. As a group, As an analyst, how much of this stuff is driven by, uh, cyber criminal syndicates that are just trying to steal money and, and how much of it is driven by nation states that are maybe collaborating in some way with those syndicates? That's a good question and I, I really wouldn't have a numbers answer for you, but I can definitely tell you that this is being utilized by both groups of those, of those.
So you have the small time who are just looking for a quick win, but you also do have those advanced persistent threats that are in nation states that are leveraging this for long-term objectives in inside companies and networks. So you've been doing this for a while. What's that one thing you see organizations doing that kind of still makes you shake your head and go, folks, we gotta be better than that.
I think if I had to pick one, I I would just, in this environment, it's, it's about embracing change and, and really trying to be proactive in thinking, um, cybersecurity is not a reactive game, at least it shouldn't be. And uh, that typically is one of the things that I'm driving home at, at my organization is for us to be proactive and think outside the box about these solutions. And to that end, it seems like to me the amount of time we have to discover and respond has been compressed greatly in the last year or so, maybe two.
Um, are people kinda aware that we're kind of fighting these games now in, uh, real time, essentially versus almost seems like you, you know, if I think back three or four years ago was a much more genteel sport, I, I definitely would agree. I think our timelines have accelerated, and I don't know how much the, you know, average user, I, I live and breathe this every day. So for me it's top of mind all the time.
Um, I certainly hope people would understand that the internet is evolving quickly as it as it always has, but it, it is always a place to approach with skepticism and always a place to approach with just that, that extra sense of caution and having a good security mindset now, now more than ever. All right folks. You heard it here.
Trust Noah. Hey Josh, thanks for being on the show. Thank you very much, Mike.
All right. And back to you guys in the studio.