Description

A new attack vector allows attackers to evade Microsoft Outlook's spam filters and send malicious ISO files to users' inboxes. This attack technique uses hyperlink obfuscation, which makes attackers camouflage malicious URLs as safe links to fool users into downloading disk image files that contain malware. In contrast to conventional phishing attacks that use social engineering or malicious attachments, this technique targets bypassing email security defenses, and thus it is harder for organizations to detect and block such threats. Security experts caution that this technique puts businesses at greater risk of malware infections, data breaches, and ransomware attacks. Hackers are targeting ISO files more and more because they are able to get around endpoint security controls that otherwise mark executable files as threats. Conventional email filtering tools isolate emails with direct links to high-risk file extensions like.iso or.exe, but this new technique conceals malicious URLs inside apparently innocuous hyperlinks. As a result, clicking the disguised link initiates the download of a malicious ISO file, which, when extracted and executed, installs malware, spyware, or ransomware on the victim's system. Since ISO files are not inherently suspicious to many security tools, attackers can easily embed harmful scripts within them without triggering traditional antivirus alerts. In order to counteract this threat, organizations need to strengthen their email security measures with the use of sophisticated URL scanning that examines the actual destination address of in-place links, instead of merely viewing their visible surface. Endpoint Detection and Response solutions need to be installed to be on the lookout for malicious file runs. It is also imperative that employees regularly undergo cybersecurity education to identify obscured phishing attacks and refrain from playing with unfamiliar-looking email attachments and links. Until Microsoft refreshes Outlook's spam filtering features, companies need to stay on their toes and actively enhance their email security infrastructure.?