Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - BEC - Redline Stealer Dominates: VIPRE’s Q3 Report Highlights Sophisticated BEC Tactics and Evolving Malware Trends
BEC Attacks Emerging Threats Latest News News & Analysis Study & Research Threat Intelligence Threats and Vulnerabilities

Redline Stealer Dominates: VIPRE’s Q3 Report Highlights Sophisticated BEC Tactics and Evolving Malware Trends

Dilki RathnayakeBy Dilki RathnayakeNovember 1, 2024Updated:November 8, 20243 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Redline
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

VIPRE Security Group’s Q3 2024 Email Threat Trends Report reveals the increasing sophistication of email-based threats, particularly business email compromise (BEC) and malspam campaigns, which have intensified across industries. Analyzing 1.8 billion emails globally, of which 208 million were identified as malicious.

As email security advances, cybercriminals are using more sophisticated tactics to evade detection. They often disguise harmful attachments, such as PDFs and DOCX files, as harmless voicemails or urgent security updates to trick recipients.

VIPRE’s Chief Product and Technology Officer, Usman Choudhary, commented, “BEC and phishing attacks are becoming more targeted and convincing, highlighting the critical need for advanced cybersecurity measures and employee education—especially as cybercriminals prepare for the upcoming holiday season.”

Manufacturing Sector Under Siege

BEC incidents targeting the manufacturing sector climbed sharply from 2% in Q1 to 10% in Q3. VIPRE’s report suggests this increase may be due to the sector’s high reliance on mobile access, leaving employees more susceptible to phishing attacks while working remotely or on the go. Globally, the sectors most frequently targeted by BEC, phishing, and malspam emails this quarter were manufacturing (27%), energy (23%), and retail (10%).

BEC Scams are on the Rise with New Impersonation Tactics

In Q3, BEC attacks made up 58% of phishing threats, with impersonation tactics playing a central role. VIPRE reports that 89% of BEC attacks involved posing as authority figures—such as CEOs, executives, and IT staff—showcasing cybercriminals’ strategic understanding of organizational roles and exploitation of employee trust. Notably, 36% of BEC samples analyzed in Q3 were generated using AI, with cybercriminals leveraging generative AI to craft convincing BEC content. These findings underscore a heavy reliance on social engineering to deceive employees into sharing sensitive information or authorizing fraudulent transactions.

URL Redirection and Phishing Links

URL redirection continues to be a favored phishing technique, accounting for 52% of phishing attempts. By embedding a “clean” link in emails, attackers are able to redirect unsuspecting users to malicious sites, bypassing initial security screenings. This tactic further complicates email defenses, emphasizing the need for security solutions capable of analyzing URLs dynamically. Compared to the previous quarter, threat actors have increased their use of attachments in malicious campaigns (30% in Q3 versus 21% in Q2), with a corresponding slight decrease in the use of links and QR codes.

Redline Stealer: The Malware Family of the Quarter

For the third consecutive quarter, Redline Stealer emerged as the top malware family, primarily distributed via phishing emails. This malware targets sensitive data from web browsers, including login credentials and payment details, using a customizable file-grabber to focus on specific file types, which highlights its ongoing threat to organizations. Redline’s continued dominance illustrates the staying power of well-engineered malware and the ongoing need for proactive defense measures.

A Wake-up Call for Organizations

Cybercriminals are not just refining their techniques but also adapting to the existing defensive measures in place. The shifting focus from general malware to highly personalized BEC scams requires organizations to stay vigilant and responsive to emerging threats. These findings underscore the urgent need for businesses to invest in adaptive, behavior-focused security tools and to cultivate a culture of security awareness. Implementing multi-layered email defenses and advanced threat detection will be essential in countering the evolving tactics of cybercriminals.

For further insights and details, access the full VIPRE Q3 2024 Email Threat Report.

Dilki Rathnayake
Dilki Rathnayake

Dilki Rathnayake is a cybersecurity content writer and the Managing Editor at Information Security Buzz, with a BSc in Cybersecurity and Digital Forensics. She is skilled in computer network security and Linux system administration. Dilki has also led awareness programs and volunteered for communities promoting best practices for online safety.

  • Dilki Rathnayake
    The new rules of war have no rules
  • Dilki Rathnayake
    AI Malware Arrives: Google Uncovers a New Wave of Adaptive Attacks
  • Dilki Rathnayake
    Out of Office, Not Out of Mind: Staying Cyber-Smart Over the Holidays
  • Dilki Rathnayake
    The Real Purpose of the UK’s Online Safety Act: An Expert Explains

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Who Can You Trust?

February 19, 20265 Mins Read

Beyond Phishing: Why AI Is Critical in BEC Detection and Forensics

October 2, 20256 Mins Read

Your Microsoft 365 Email Security Needs a Smarter Ally

August 22, 20255 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}