A New Spear Phishing Attack Uses Compromised Government Servers And DNS

Share and earn Cybytes
Facebook Twitter LinkedIn Email

Cisco’s Talos malware researchers posted about a highly sophisticated, targeted spear phishing attack using malicious Word attachments, spoofed to look like it was from the U.S. Securities and Exchange Commission EDGAR filing system, and used DNS to create a bidirectional Command & Control channel. The Word attachments contained SEC logos and branding, social engineering the user to believe that the emails were legit and click on prompts.

Using this channel, the attackers were able to abuse the Microsoft DDE protocol which allows dynamic data exchange between applications, and use the contents of DNS TXT record queries and the associated responses generated on the attacker-controlled DNS server. The targets included insurance, finance, and IT companies.

Share this post and earn Cybytes
Facebook Twitter LinkedIn Email
About KnowBe4
KnowBe4 is the world’s largest security awareness training and simulated phishing platform that helps you manage the ongoing problem of social engineering. The KnowBe4 platform is user-friendly and intuitive. It was built to scale for busy IT pros that have 16 other fires to put out. Our goal was to design the most powerful, yet easy-to-use platform available. Customers with businesses of all sizes can get the KnowBe4 platform deployed into production at least twice as fast as our competitors. Our Customer Success team gets you going in no time, without the need for consulting hours.
Promoted Content
Free IT Security Tools
We have developed a set of free IT security tools that all help to strengthen your network and your last line of defense against cybercrime: users. Protect yourself against phishing, malware, bad passwords, email threats and more. Try one or try them all!

Our Revolution

We believe Cyber Security training should be free, for everyone, FOREVER. Everyone, everywhere, deserves the OPPORTUNITY to learn, begin and grow a career in this fascinating field. Therefore, Cybrary is a free community where people, companies and training come together to give everyone the ability to collaborate in an open source way that is revolutionizing the cyber security educational experience.

Cybrary On The Go

Get the Cybrary app for Android for online and offline viewing of our lessons.

Get it on Google Play

Support Cybrary

Donate Here to Get This Month's Donor Badge

Skip to toolbar

We recommend always using caution when following any link

Are you sure you want to continue?