Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - One In Every 359 Emails Are Carrying A Malicious Payload
News & Analysis

One In Every 359 Emails Are Carrying A Malicious Payload

ISBuzz TeamBy ISBuzz TeamAugust 14, 2017Updated:December 4, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

It has been reported that the number of emails carrying malware increased to a new high in July with one in every 359 emails carrying a malicious payload, according to Symantec’s July Intelligence Report.

July also saw increases in the number of phishing attempts and spam, but the increasing use by cybercriminals of email to spread malware took center stage reaching a level not seen since December 2016. IT security experts commented below.

Bill Evans at One Identity: 

“Recently, the Symantec July Intelligence Report noted that there has been an increase in phishing attempts and spam.  In addition, the report goes on to state there has been a resurgence in the use of email by cybercriminals to levels not seen since December 2106.

This really is not that surprising.  Cybersecurity, cybercrime, cyberhacking – it’s all a very deliberate dance between the forces of good and evil.  Each time the cyberbad guys make a change to their modus operandi (MO), the cybergood guys evolve their solutions to address the new challenge.  As stated in the Symantec report, it appears that the cyberbad guys have now adapted their e-mail based malware to actually steal email addresses and essentially send itself out in a “respam” method.  This adaptation will significantly increase the percentage of emails carrying malware.  In the next phase of the dance, it can be assumed with some certainty that the cybergood guys will adapt their solutions to identify and block this sort of cybernuisance.  And then dance will continue.”

Mark James, Security Specialist at ESET:

“With so many of our devices now able to compose, send and receive emails from almost anywhere in the world, it’s no wonder that email is the number one attack vector for starting a cyber-attack. When that email lands in your inbox, regardless of whether you know its fake, there is often an urge to open it just to make sure. We as humans are naturally curious, we want to make sure, we want to believe others are trustworthy- but in the end it often proves to us what we and almost everyone else thinks; that so many emails are only there to trick us into spreading doom and gloom, either physically or metaphorically.

Teaching our users the need to understand, spot and report potentially dodgy emails is extremely important, and has proven its worth in gold. But it needs to happen consistently and evolve around current threats- the same lecture every morning will end up falling on deaf ears, but with current attack methods and real life examples leading into reasons on how and why it can cause the worst case problems we often see leading to huge data breaches, can help the staff to become important members of the security team and not just the weakest link.

Emails are a very important part of not only our business life, but our personal as well. We need them and more often than not we have to open them- but spotting the good from the bad is not always as easy as it seems.”

Lee Munson, Security Researcher at Comparitech.com:

“Cyber criminals have used email to deliver bad things to unsuspecting victims ever since the technology first gained widespread adoption and the presence of malware across the messaging system is nothing new.

That Trojans and other nasties are now appearing at a faster rate than the recently popular phishing and ransomware attack vectors should be seen as troubling though.

Given the fact that recent press and security awareness commentary has been preoccupied by the former, many people could have taken their eyes off the ball where malware is concerned, potentially leaving their bank accounts at risk of fraud and their inboxes swamped by spam.

With 1 in every 359 emails containing a malicious payload, everyone should follow basic security tips such as checking the sender of every email they receive, not clicking on links in messages or opening attachments unless certain of their destination and never allowing macros to run on their devices.”

Javvad Malik, Security Advocate at AlienVault:

Javvad Malik“It’s not surprising to see emails remain a favoured attack vector for criminals. The ease at which email lists can be obtained and spammed indiscriminately puts the odds in favour of the criminals. It also increases the likelihood of success as each recipient usually has more than one device upon which they would read the email.”

“We also continuously see email indicators being added to the Open Threat Exchange (OTX) on a regular basis which helps organizations to detect and respond to malicious emails. https://otx.alienvault.com/browse/pulses/?q=email&sort=-created ”

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Foxconn confirms cyberattack following Nitrogen ransomware claims

May 14, 20263 Mins Read

Lazarus Group Turns to Medusa Ransomware in Escalating Global Extortion Campaign

February 26, 20263 Mins Read

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}