top of page
Search

Mailbombing Attacks

  • Tom Foale
  • Nov 22, 2024
  • 1 min read

There is a current mail-bomb cyberattack underway on multiple businesses, large and small. Users are being targeted with large numbers of emails from legitimate sites they may never have ever visited, asking them to confirm subscriptions to sites and services, reset their passwords or download files.


This is a distraction attack. The intent is to install malware on user devices via a zip file downloaded from a script. The emails may be followed by a Teams message or phone call from 'Microsoft support' or 'IT support'. The imposter persuades the user to install Anydesk and uses this to install malware on the user's device.


This attack has been confirmed by Mimecast and Crowdstrike. It can be blocked by blocking installations of Anydesk, tightening email rules on Defender or your email gateway, or creating filter rules that detect words such as "welcome", "subscribe', "subscription" or "password". Also, blacklisting the Anydesk site for your users will help.


Alongside these measures and alerting your users we would recommend using Deep Instinct, which detects and stops any attempt to install malware, including from scripts and zip files and even zero-days, in less than 20ms.

 
 
 

Comments


OPENING HOURS

Monday – Friday: 09:00 - 17:30 
Saturday – Sunday: Closed

FOLLOW US

  • Facebook
  • Google business
  • LinkedIn
  • X
Review us on Yell logo

KLAATU IT SECURITY LIMITED, registered as a limited company in England and Wales under company number: 10940431.
Registered Company Address: 29 Devizes Road, Swindon, Wiltshire, SN1 4BG.

Terms of Use | Privacy & Cookie Policy | Trading Terms

© 2025. The content on this website is owned by us and our licensors. Do not copy any content (including images) without our consent.

bottom of page