Le Lézard
Classified in: Science and technology
Subject: Survey

Browser-Based Phishing Attacks Increased 198% in 2023 as Threat Actors Grow More Evasive, Menlo Security Research Finds


Menlo Security, a leader in browser security, today released its 2023 State of Browser Security Report, demonstrating rapid growth of Highly Evasive Adaptive Threats (HEAT) targeting the browser. The research uncovered a 198% increase in browser-based phishing attacks in the second half of 2023 compared to the first half of the year. When specifically looking at attacks classified as evasive, the researchers observed a 206% increase.

Evasive attacks ? those that utilize a range of techniques meant to evade traditional security controls ? are growing at a faster rate than other types of browser-based phishing attacks because cybercriminals know they have a higher rate of success employing these methods. Evasive threats now make up 30% of total browser-based phishing attacks and include tactics such as SMS phishing (smishing), Adversary in the Middle (AITM) frameworks, image-based phishing, brand impersonation or Multi-Factor Authentication (MFA) bypass. The full 2023 State of Browser Security Report contains additional details on these tactics.

Browser usage across managed and unmanaged devices has skyrocketed in recent years, exposing an immense attack surface enterprises are grappling to cover. Traditional network-based security controls unfortunately aren't detecting zero-hour phishing attacks that deliver ransomware and steal credentials. Over a 30-day period, the Menlo Labs Threat Research team observed more than 11,000 zero-hour phishing attacks that exhibited no signature or digital breadcrumb, meaning no existing Secure Web Gateway (SWG) or endpoint tool could detect and block those attacks. The team also discovered that 75% of phishing links are hosted on known, categorized or trusted websites ? not websites that can be easily identified as malicious or fly-by-night websites.

"Humans remain the weakest link in the cybersecurity chain ? unintentionally divulging corporate credentials and secrets ? and threat actors have decidedly shifted focus to web browsers as THE point of entry to gain initial access," said Amir Ben-Efraim, Co-Founder and Chief Executive Officer of Menlo Security. "Menlo Security is continuously detecting and preventing an influx of new browser-based phishing campaigns that are highly targeted, sophisticated and evasive, bypassing traditional network and email-based detection tooling. It's imperative that CISOs focus their defenses on browser security as the only effective prevention strategy against these modern threats."

To compile this report, the Menlo Labs Threat Research team examined threat data and browser telemetry gathered from Menlo Security Cloud, including over 400 billion web sessions during 2023. Additionally, the team took a closer look at a 30-day period in Q4 2023 to glean more specific insights about cybercriminals' evolving tactics and attack patterns. Other key findings from the State of Browser Security Report include:

"Evasive techniques are handcrafted to fly under the radar and are particularly hard for security teams to spot. Unfortunately, modern security tooling such as SWG and Endpoint Security are ineffective as attackers are able to bypass these protections," said Devin Ertel, Chief Information Security Officer of Menlo Security. "However, our research found that browser security was able to stop these zero-hour phishing attacks even when they exhibited sophisticated evasion. Organizations must adopt a targeted approach to browser security by leveraging various AI-based approaches ? including object detection, URL risk assessment, and web page element analysis ? to fight against today's evasive cyber threats."

Download the full 2023 State of Browser Security Report to read the findings and see how today's threat actors are evading traditional security tooling.

To learn more about how browser security can eliminate the browser attack surface, visit Menlo Security's platform overview page or schedule a demo to learn how Menlo Security can protect your organization against zero-hour phishing, malware, and ransomware attacks targeting the browser.

About Menlo Security

Menlo Security protects organizations from cyber threats that attack web browsers. Menlo Security's patented Cloud-Browser Security Platform scales to provide comprehensive protection across enterprises of any size, without requiring endpoint software or impacting the end user-experience. Menlo Security is trusted by major global businesses, including Fortune 500 companies, eight of the ten largest global financial services institutions, and large governmental institutions. The company is backed by Vista Equity Partners, Neuberger Berman, General Catalyst, American Express Ventures, Ericsson Ventures, HSBC, and JPMorgan Chase. Menlo Security is headquartered in Mountain View, California. For more information, please visit www.menlosecurity.com.


These press releases may also interest you

at 11:30
Top-tier VR accessories provider KIWI design has launched its latest product, the RGB Vertical Stand. This Meta-authorized accessory, designed to deepen users' immersion in the metaverse, is now available on the official Meta website....

at 10:45
eBlu Solutions, a leading provider of innovative technology solutions for the specialty healthcare industry, is pleased to announce the addition of Doug Lawrence to the Executive Leadership team in the role of Chief Revenue Officer. "We're not just...

at 10:31
On May 9, The 8th Global ICT Energy Efficiency Summit, themed "Green Site, Building a Brighter Future", was held in Bangkok, Thailand. At this summit, Site Power Facility Domain of Huawei Digital Power launched the All-Scenario Smart Telecom Power...

at 09:05
Cardurion Pharmaceuticals, Inc. ("Cardurion"), a clinical-stage biotechnology company developing next-generation therapeutics for the treatment of cardiovascular diseases, today announced the presentation of positive clinical data from CARDINAL?HF,...

at 09:00
From May 7th to May 9th, 2024, TCT ASIA 2024 was held at the National Exhibition and Convention Center in Shanghai. As a global summit for 3D printing technology, this exhibition brought together numerous industry elites and research experts to...

at 08:00
The ninth annual United Nations Science, Technology, and Innovation Forum (UN STI Forum), dedicated to advancing the Sustainable Development Goals, convened at the UN headquarters in New York on May 9-10, 2024. Under the theme "Science, Technology,...



News published on and distributed by: