Cofense Annual Email Security Report 2024

Major cybersecurity vendors’ annual email security reports highlight the rise of sophisticated phishing tactics and malware families, emphasizing the increasing threat landscape in 2024. Key statistics reveal a 104.5% surge in malicious emails bypassing security gateways and a focus on evolving attack vectors like credential theft, QR codes, and brand impersonation. #DarkGate #PikaBot

Keypoints

  • Annual cybersecurity reports typically consist of sections such as an introduction, numerical data on threat trends, detailed analysis of attack techniques, and future threat predictions, providing a comprehensive overview of the current cybersecurity landscape.
  • In 2024, reports consistently reveal a more than 100% increase in malicious emails bypassing secure email gateways (SEGs), with Cofense detecting a malicious email every minute, underscoring the effectiveness of threat actors’ evasive tactics.
  • Credential phishing remains the dominant threat, responsible for 91% of active threat reports, with a 67% increase from the previous year, utilizing techniques like vishing, smishing, and QR code phishing, which have seen a 331% rise in activity.
  • Phishing campaigns are adopting new methods such as Google AMP URLs to evade detection, while threat actors increasingly use brand impersonation and vishing to manipulate victims and bypass traditional security controls.
  • Emerging malware families including DarkGate, PikaBot, Emotet/Geodo, Agent Tesla, FormBook, and Snake Keylogger illustrate the evolving malware landscape, with new campaigns replicating tactics from previously dismantled infrastructures like Qakbot.
  • Reports highlight the exploitation of social engineering tactics and advanced malware delivery chains, emphasizing the necessity for comprehensive security strategies combining user training with advanced detection tools to counteract these evolving threats.
Cofense-Annual-State-of-Email-Security-2024
Source: Awesome Annual Security Reports - The reports in this collection are limited to content which does not require a paid subscription, membership, or service contract. (https://github.com/jacobdjwilson/awesome-annual-security-reports/)

Download Report from Github