Security News Just Five File Types Make Up 85% of All Spam Malicious Attachments

LASER_oneXM

Level 37
Thread author
Verified
Top Poster
Well-known
Feb 4, 2016
2,520
Despite a lone report claiming that online piracy is the primary source of malware, spam still reigns supreme as today's main infection vector and the go-to tool of online criminals, according to a report published yesterday by Finnish cyber-security firm F-Secure.

Experts say that one of the main reasons why spam still works is that users are still failing at recognizing spam. Users are having a hard time picking up spam despite spam being more than a 40-year-old trick. This has led to users clicking on spam emails more than ever.

Spam click rates are up

F-Secure reports that spam email click rates have gone up from the 13.4% recorded in the second half of 2017 to 14.2% recorded in the first half of the year.
With browsers and operating systems getting harder to hack via exploit kits and vulnerabilities, spam has been the safety net on which most cybercriminal operations have fallen on.

"Of the spam samples we’ve seen over spring of 2018, 46% are dating scams, 23% are emails with malicious attachments, and 31% contain links to malicious websites," said Päivi Tynninen, Threat Intelligence Researcher at F-Secure.

"We’ve found that just five file types make up 85% of malicious attachments," Päivi added. "They are ZIP, .DOC, .XLS, .PDF, and .7Z."
 

Andy Ful

From Hard_Configurator Tools
Verified
Honorary Member
Top Poster
Developer
Well-known
Dec 23, 2014
8,040
"They are .ZIP, .DOC, .XLS, .PDF, and .7Z."
DOC, XLS, PDF = most popular document extensions; many exploits + embedded macros & scripts; dangerous especially when the user has installed MS Office or Adobe Acrobat Reader.
ZIP, 7Z = files decompressed by 3rd party software usually are not recognized as downloaded from the Internet, so they are ignored by SmartScreen and documents are not opened in Protected View.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top