Russian and Iranian spear-phishing in the UK: Are your defences up?
Russia-based group SEABORGIUM and Iran-based group TA453 are targeting UK organisations, individuals and decision makers with spear-phishing campaigns.
Spear-phishing, like phishing, involves malicious links being sent via email, social media or professional networking platforms but with the difference of being highly targeted at key individuals. These campaigns are focused on gathering high-value and advantageous information.
Attackers carry-out reconnaissance around the most influential people in an organisation. They build a sense of trust by pinpointing key information and build a rapport before they strike. Attackers might impersonate real-world contacts of their targets, send false invitations to conferences and events, and share malicious links disguised as Zoom meeting URLs.
These types of attack are most prevalent in specific sectors, including academia, defence, government organisations, NGOs, think-tanks, as well as politicians, journalists and activists. However, Absolute Networks Ltd urge all organisations and individuals to stay vigilant to potential approaches and take action to secure online accounts.
Absolute Networks Ltd's Cyber Security Specialists can help your organisation mitigate the risks of spear-phishing activity. Some ways this might be achieved include:
- Enforcing a strong password policy for email accounts following industry best practice recommendations
- Recommending and implementing enhanced email scanning software
- Enabling multi-factor authentication
- Protecting your organisation's devices and networks by keeping them up-to-date
- Preventing email forwarding rules
- Raising awareness of spear-phishing techniques
Connect with our experienced and knowledgeable team to start developing your organisation's Cyber Security strategy: 01332 291992 or info@absolute-networks.co.uk
Recent Posts
Is it time for a company policy on the use of ChatGPT and other LLMs?
IT Support Large language models (LLMs) have rapidly popularised since the launch of ChatGPT at the end of 2022. As an emerging technology there are many security unknowns but considering [...]
Russian and Iranian spear-phishing in the UK: Are your defences up?
IT Support Russia-based group SEABORGIUM and Iran-based group TA453 are targeting UK organisations, individuals and decision makers with spear-phishing campaigns. Spear-phishing, like phishing, involves malicious links being sent via email, [...]
Charities Beware: You’re a target!
IT Support The lowest of the low! Cyber criminals see UK charities as easy pickings. Here's why charities are particularly vulnerable to cyber attacks: Regularly handle donations Hold sensitive and [...]
Is your business guilty of phishing ‘blame and fear’? Is there another way?
IT Support You hear a knock at the door and go to answer it. As you open the door the person on the other side barges past you, into your [...]
Strong Passwords, blah, blah, blah! But what really is a strong password policy in 2023?
IT Support Most are fully aware that passwords are the gateway to your business systems and therefore weak passwords represent a massive vulnerability. Weak passwords are a form of human [...]