Cybercriminals are changing their tactics when it comes to phishing attacks and are increasingly leveraging malicious domain registrations. The Anti-Phishing Working Group (AWPG) recently released a report that detailed how malicious use of the domain name system reached an all-time high in 2016. The study showed that malicious domain registrations accounted for half of all domain names used for phishing in 2016.

How Phishing Attacks Use Domains

Authors of the report, titled “Global Phishing Survey: Trends and Domain Name Use in 2016,” suggested the shift from hacked web servers and domains to malicious domain registration signifies phishers are becoming bolder in their activities and actions.

The AWPG report explained there were at least 255,065 unique phishing attacks globally during 2016. Of the 195,475 domains used for phishing, 95,424 domain names were maliciously registered by phishers — almost three times the total for 2015.

Domains have become a key element in the cybercriminal arsenal. Phishers set up webpages that masquerade as trustworthy brands, such as banks and e-commerce sites. Cybercriminals can then lure victims to these fake sites, and users are tricked into providing sensitive information such as usernames, passwords and credit card details.

Big Names, Big Targets

Cybercriminals often use phishing schemes to target big-name brands. E-commerce giants PayPal, Yahoo, Apple and more had more than 30,000 phishing attacks against their respective services through 2016, the study found. Together, these brands were the targets of more than half (57 percent) of global phishing attacks.

The study also revealed many domains used by phishers are being aged and are not used immediately. New domains receive low reputation scores from security and antispam companies, which makes it more likely the phishing emails will be flagged before reaching intended victims. Cybercriminals evade those measures by waiting until registered domains are older and have better reputation scores.

More Tricks in the Phishing Game

Experts have long warned that cybercriminals evolve and adapt to bypass industry safeguards. For example, in May, researchers at Netcraft referred to a sharp hike — from roughly 5 percent to 15 percent — in the number of phishing sites using HTTPS to communicate since the start of the year.

Greg Aaron, vice president of iThreat Cyber Group and report co-author, recognized in a press release that phishers are using other tricks, such as domain shadowing, to further their schemes. Domain shadowing is when an unsuspecting company’s DNS settings are manipulated to insert multiple phishing sites onto the firm’s servers.

While phishing attacks can affect any business, the report said assaults remain focused on a few key industries: Finance, e-commerce, social networking and money-transfer companies are the target for the vast majority (92 percent) of phishing attacks.

News of the shift in techniques used by phishers highlighted how cybercrime detection and mitigation problems affect the domain name industry. The study’s authors suggested businesses take strong measures to protect their web hosting and email services. Users, meanwhile, must always be alert when they enter credentials and should pay close attention to the destination URL for any site they are using.

More from

Is It Time to Start Hiding Your Work Emails?

In this digital age, it is increasingly important for businesses to be aware of their online presence and data security. Many companies have already implemented measures such as two-factor authentication and strong password policies – but there is still a great deal of exposure regarding email visibility. It should come as no surprise that cyber criminals are always looking for ways to gain access to sensitive information. Unfortunately, emails are a particularly easy target as many businesses do not encrypt…

2022 Industry Threat Recap: Finance and Insurance

The finance and insurance sector proved a top target for cybersecurity threats in 2022. The IBM Security X-Force Threat Intelligence Index 2023 found this sector ranked as the second most attacked, with 18.9% of X-Force incident response cases. If, as Shakespeare tells us, past is prologue, this sector will likely remain a target in 2023. Finance and insurance ranked as the most attacked sector from 2016 to 2020, with the manufacturing sector the most attacked in 2021 and 2022. What…

X-Force Prevents Zero Day from Going Anywhere

This blog was made possible through contributions from Fred Chidsey and Joseph Lozowski. The 2023 X-Force Threat Intelligence Index shows that vulnerability discovery has rapidly increased year-over-year and according to X-Force’s cumulative vulnerability and exploit database, only 3% of vulnerabilities are associated with a zero day. X-Force often observes zero-day exploitation on Internet-facing systems as a vector for initial access however, X-Force has also observed zero-day attacks leveraged by attackers to accomplish their goals and objectives after initial access was…

And Stay Out! Blocking Backdoor Break-Ins

Backdoor access was the most common threat vector in 2022. According to the 2023 IBM Security X-Force Threat Intelligence Index, 21% of incidents saw the use of backdoors, outpacing perennial compromise favorite ransomware, which came in at just 17%. The good news? In 67% of backdoor attacks, defenders were able to disrupt attacker efforts and lock digital doorways before ransomware payloads were deployed. The not-so-great news? With backdoor access now available at a bargain price on the dark web, businesses…