Trick or Treat Security Scares

happygeek 0 Tallied Votes 426 Views Share

You probably call it Halloween, for myself and other pagans it is Samhain, but for the cyber-gangs it is phishing time. Seasonally-themed spam is on the up at this time of the year, Halloween related messages accounting for 0.5% of the daily spam traffic by volume in mid-October according to the latest Symantec MessageLabs Intelligence Report.

Currently, with the 'Witch's New Year' Sabbath itself coming this weekend, there are some 500 million emails circulating worldwide and the majority of the Halloween spam is originating from the Rustock and Donbot . Most of this would appear to be pointing towards pharmaceutical sites and rogue/counterfeit software sites.

"As is typical with spammers this time of year, we are seeing them try to capitalize on the holiday season" said MessageLabs Intelligence Senior Analyst, Paul Wood. "Although they may be a bit overzealous, spamming is a numbers game and the spammers have certainly succeeded with volume thus far. Perhaps their early-bird approach is an attempt to compete with the other botnets and get in early to maximize their chances of success."

This month has also seen a batch of intercepted event-related advance-fee fraud spams, mostly relating to the 2010 football World Cup in South Africa which try and get the target to pay an up front fee in order to supposedly receive their prize draw winnings.

The October phishing activity has been 1 in every 293.7 emails, an increase of 0.11% since September but a drop of 10.5% if looked at as a proportion of all email-borne threats.

When it comes to viruses, October has seen the global ratio of email-borne viruses in email traffic from new and previously unknown bad sources increase by just 0.18% from September to 1 in every 230.8 emails. However, only 19.2% of email-borne malware contained links to malicious websites, which is a huge drop of some 20.6% from the previous month.

Geographically speaking, Denmark was the most spammed country with levels of 96.2 percent of all email, with the US on 94% and the UK on 93.3% while China tops the virus activity charts though, with 1 in every 80.7 emails being infected.

Dani AI

Generated

As observed, attackers commonly reuse seasonal themes to increase click rates. Practical, time-tested controls are far more useful than old statistics when a suspicious, themed message appears. Recommended immediate actions include:

  • Treat unsolicited links or attachments as suspicious; preview links by hovering or copying the URL and resist enabling macros or executables in attachments.
  • Verify unexpected requests through an independent channel (official website or a previously known phone number), not the contact details supplied in the message.
  • Require multi-factor authentication on important accounts and prefer phishing-resistant options (security keys or modern authenticator apps).
  • Preserve evidence by forwarding suspicious messages “as attachment” to internal responders or to reporting services such as the APWG, and report financial losses to IC3/FTC if money was requested or lost.
    APWG Phishing Activity Trends Reports (apwg.org)

Email-gateway and endpoint protections matter. Time-of-click URL scanning and attachment sandboxing significantly reduce successful deliveries; enable those features where available (for example, Safe Links and Safe Attachments). If a link or attachment was opened, assume credentials or the device may be compromised: isolate the endpoint, reset exposed credentials, and follow incident‑response procedures. For privileged and remote-access accounts, enforce phishing-resistant MFA and minimize privilege scope.
Safe Links documentationSafe AttachmentsCISA MFA guidance. (learn.microsoft.com)

Operational steps for domain owners: publish SPF and DKIM, then deploy DMARC in monitoring mode (p=none) to collect aggregate reports (rua). Fix alignment and third‑party senders, then move to quarantine and finally reject when confident. Example DMARC TXT (replace example addresses and domain):

_dmarc.example.com.  IN  TXT  "v=DMARC1; p=none; rua=mailto:dmarc-agg@example.com; pct=100; aspf=s; adkim=s"

Use provider guides when creating DNS records and scale enforcement slowly while monitoring reports. Also combine DNS authentication with gateway sandboxing and phishing‑resistant MFA for admins.
DMARC basicsGoogle DMARC setup guidanceSPF for Microsoft 365. (dmarc.org)

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.