Phishing

Analyzing Disk-Minimal Malware in Phishing Attacks: A Forensic Methodology for Modern Cyber Threats

Abstract:

Today’s cyber threat landscape is characterized by advanced methodologies and attacks that inflict monumental damage on educational and financial institutions, healthcare systems, and information infrastructures. Among these threats, phishing remains the most effective initial vector for system compromise. The authors provide comprehensive insights into the evolving threat landscape and introduce an updated definition of fileless malware, referred to as disk-minimal malware. They propose a methodology for forensic examiners to identify and analyze the attack lifecycle of disk-minimal malware delivered through phishing attacks.

Categorising Cybercrime and Cybercriminals: The Problem and How It Has Changed

Abstract:

Twenty years ago, the Journal of Information Warfare published a paper examining the problem of cybercrime and the nature of those responsible for it. Taking its cue from the title of the original paper, this sequel begins by reflecting upon the situation of two decades ago, before jumping forward to examine the landscape of today. 

A Context-Centred Research Approach to Phishing and Operational Technology in Industrial Control Systems

Abstract:

Advanced persistent threats that leverage phishing against OT are cyberattacks that endanger critical infrastructure assets nationwide. Today phishing, a human focused exploit, constitutes 91%  of successful attack vectors against federal assets. This means Human-Introduced Cyber Vulnerabilities (HICV) are the weakest cyber link. The success of these attacks also suggests HICV are neither well understood nor mitigated. To characterise HICV and provide the necessary context in which they exist, this paper introduces a research approach derived from the mature sci-ence of social ecology. The desired end result of this research is an HICV-focused risk assessment framework.

An Assessment of End-user Vulnerability to Phishing Attacks

ABSTRACT

Phishing has grown to become a significant threat to unsuspecting Internet users. This paper investigates user susceptibility to such attacks by assessing the degree to which they can differentiate between phishing messages and those that are genuine. A web-based survey was used to present a mix of 20 legitimate and illegitimate emails, and participants were asked to classify them and explain the rationale for their decisions. A total of 179 participants were involved in the study, and results reveal that they were 36% successful in identifying legitimate emails and 45% successful in spotting illegitimate ones.  Additionally, in many cases, the participants who identified illegitimate emails correctly could not provide convincing reasons for their selections.  

Journal of Information Warfare

The definitive publication for the best and latest research and analysis on information warfare, information operations, and cyber crime. Available in traditional hard copy or online.

Keywords

A

AI
APT

C

C2
C2S
CDX
CIA
CIP
CPS

D

DNS
DoD
DoS

I

IA
ICS

M

P

PDA

S

SOA

X

XRY

Quill Logo

The definitive publication for the best and latest research and analysis on information warfare, information operations, and cyber crime. Available in traditional hard copy or online.

SUBSCRIBE NOW

Get in touch

Registered Agent and Mailing Address

  • Journal of Information Warfare
  •  ArmisteadTEC
  • Dr Leigh Armistead, President
  • 1624 Wakefield Drive
  • Virginia Beach, VA 23455

 757.510.4574

 JIW@ArmisteadTec.com