The email cyber attack threat landscape has changed considerably in the last few years, ever since the Covid-19 pandemic triggered a mass shift over to remote working.
The transfer of almost all communications to an online format has stimulated a rise in both phishing and business-email compromise (BEC) attacks. The increased volume of business communications has made it far easier for cybercriminals to infiltrate their malicious emails alongside legitimate ones, turning the mimicking of businesses correspondence into the main attack vector of 2022.
Other social engineering tricks, such as carefully worded emails and texts urging the victim to act quickly, have also been on the rise in the past year. The main email cyber attack trends we’ve seen in 2022 are:
- A substantial increase in phishing emails containing malicious content to directly infect the victim’s computer.
- Growing use of targeted social engineering techniques, similar to spear-phishing. This includes adding email signatures to mimic organisations or departments, using professional business language, featuring relevant business events, and referring to actual company employees, all to gain legitimacy.
- Continued brand spoofing – the adoption of email addresses with domains similar to existing domains in target organisations.
Malware in Emails
The main trend of 2022 has been malicious emails disguised as business communications. More malicious emails now contain malware, rather than simply carrying a link to a malicious website.
In most incidents reported last year, when a malicious attachment is opened, either the Qbot or EMotet Trojan malware is activated. Both are able to steal user data, harvest information found on corporate networks, or distribute other kinds of malware, such as ransomware. Qbot is a particularly dangerous malware, and is used to access and steal email communications, granting cybercriminals more material for future attacks.
Emails mimicking official communications from government departments have also risen considerably in tandem with major current events. Emails and SMS messages imitating government notices regarding Covid-19, the cost of living, and the Ukraine war, are just some of the many events taken advantage of by cybercriminals. Scam emails pretending to provide information on claiming cost of living payments have been particularly devastating, as families become desperate for extra financial support.
To encourage the victim to open an attachment or download a file, cybercriminals typically convince them that the attachment contains business-relevant information, such as a commercial offer, invoice, or staff details. To grant the attachment greater legitimacy in the mind of the victim, cybercriminals will often send the file in an encrypted archive, the password for which will be given in the body of the email. Such malicious emails often feature more personalisation than traditional phishing emails, with the cybercriminals paying attention to detail and using the branding and phrasing of a relevant organisation, such as a customer, partner, or supplier. Such an email cyber attack typically marks the start of a more sophisticated BEC attack.
What is a BEC attack?
A business email compromise attack is a highly targeted cyber attack campaign with several stages:
- The cybercriminal initiates an email exchange with a company employee, or manages to take over an employee’s email.
- The cybercriminals gains the trust of a different employee (typically one with greater privileges or access rights, such as a manager or director)
- The cybercriminal encourages the employee to take action that is harmful to the company, such as transferring funds, granting access to a network, or directly leaking data.
An increasingly common harmful action encouraged by cybercriminals is the purchasing of gift cards. These requests often appear to come from the company’s owner or CEO.
Although BEC attacks often employ phishing tactics, they are somewhat more sophisticated, drawing from both technological expertise and social engineering. BEC attacks also have a natural advantage over phishing emails, as they contain no malicious links or attachments, but instead work to directly trick the recipient into believing that the cyber criminal and their malicious request are legitimate.
BEC attacks can manifest as just two or three messages, or they can be complicated and strategic attacks lasting several months. Multistage BEC attacks, which combine various scenarios, have also seen an increase. An example of such an attack is where cybercriminals first steal the credentials of an mid-level employee using a traditional phishing email, and then use those credentials to launch a sophisticated social engineering attack against a higher-ranking employee, who will have access to more valuable data, or be able to make larger payments.
How to protect your organisation
Cyber attacks are becoming increasingly sophisticated every year, and 2022 was no exception. New methods of mimicking business correspondence are constantly appearing, and becoming increasingly convincing.
To keep your corporate infrastructure protected against email attacks, its important to have effective synergy between both your technical security measures and your organisational practices. This means partnering with an experienced managed security service provider, such as TecSec, who can provide both effective threat detection & response measures, and implement regular security awareness training and procedures throughout your organisation.







