DigitalCIO
No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
DigitalCIO
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
No Result
View All Result
Digitalcio
No Result
View All Result
Home Tech News

Phishing emails using Adobe InDesign on the rise, Barracuda Threat Spotlight reveals

DigitalCIO Bureau by DigitalCIO Bureau
December 6, 2023
in Tech News
0
Phishing emails using Adobe InDesign on the rise, Barracuda Threat Spotlight reveals
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

Barracuda, a leading provider of cloud-first security solutions, has unveiled a new Threat Spotlight in which security researchers at Barracuda are warning of a recent surge in phishing attacks leveraging Adobe InDesign, a known and trusted document publishing system. Some of the attacks are targeted.

According to Barracuda telemetry, there has been a near 30-fold increase since October in emails carrying Adobe InDesign links. The daily count has jumped from around 75 per day to around 2,000 per day. Almost one in 10 (9%) of these emails carry active phishing links. A further 20% or so include removed content.

Many of the phishing links seen by Barracuda researchers have the top-level domain of “.ru” and are hosted behind a content delivery network (CDN) that acts as a proxy for the source site. This helps to obscure the source of the content and makes it harder for security technologies to detect and block the attacks.

Advanced to very basic attacks

Some of the attacks leveraging Adobe InDesign appear to be targeted at specific organizations or users. These emails carry legitimate brand logos that have probably been copied from other content or scraped from websites by the attackers. The logos are likely to have been chosen because they are known and trusted by the targets — and suggest the attackers spent time and resources crafting these messages.

The rest of the attacks are mainly generic mass-distributed messages featuring the OneDrive, SharePoint, and Adobe logos.

Some feature very basic text, pulled together with minimal effort.

All the attacks are relatively straightforward and consistent in their approach, inviting the recipient to click on a link that will take them to another site, hosted on the indd.adobe[.]com sub domain but actually controlled by the attackers, for the next stage of the attack.

Why these attacks succeed

Phishing attacks continue to evolve to become more sophisticated, deploying different techniques and tactics to bypass security detection and trap victims.

The attacks leveraging Adobe InDesign employ several tactics to evade detection and trick targets.

  • First, they leverage a known and trusted domain that is not commonly block listed.
  • Second, by using a publishing program they can create highly convincing social engineering attacks.
  • Third, once the recipient clicks on the link, they are moved to another web page. This means that there is no known malicious URL link in the main body of the message for traditional security tools to detect and block.
  • Fourth, for those attacks hosted behind the CDN, this further helps to obscure the malicious source of the content and makes it harder for security technologies to detect and block.

 

How to stay safe

To stay protected it is important to have advanced, multilayered and AI-powered email security in place, capable of spotting emerging as well as known threats.

This should be accompanied by regular cybersecurity awareness training for employees. The training should be updated whenever new threat trends appear so that employees know what to look out for and what to do if they spot a suspicious or malicious email.

Barracuda’s detection data shows that some of the phishing attacks leveraging Adobe InDesign targeted multiple employees within the same organization — and the rapid reporting of and response to such attacks can stop it in its tracks.

Barracuda LinkProtect

Barracuda Email Protection includes a link protection capability to ensure users do not click on any malicious URLs.

LinkProtect wraps every link in an email that passes through its gateway product, and an analysis is performed at time of click of every URL to identify if the link is good or bad. In addition, LinkProtect’s ability to act as a protective layer between the email and the recipient is critical because it serves as the last line of defense in case the threat is new or unknown.

Tags: Barracuda
Share30Tweet19
DigitalCIO Bureau

DigitalCIO Bureau

Recommended For You

Fractal unveils intelligent sales agents to accelerate B2B growth

by DigitalCIO Bureau
March 11, 2026
0
Fractal unveils intelligent sales agents to accelerate B2B growth

Flyfish.ai now deploys 35+ coordinated AI agents across the sales lifecycle, helping early enterprise adopters close deals up to 30% faster and improve sales productivity by 42%. Fractal...

Read moreDetails

TCS Named a Leader in Artificial Intelligence and Generative AI Services by Everest Group

by DigitalCIO Bureau
March 11, 2026
0
TCS Named a Leader in Artificial Intelligence and Generative AI Services by Everest Group

Cited as key strengths are Tata Consultancy Services platform-led AI transformation strategy, proprietary industry assets, and strong co-innovation with partners Tata Consultancy Services (TCS), has been positioned as...

Read moreDetails

SEI Engages IBM to Accelerate Enterprise Transformation Through Agentic AI

by DigitalCIO Bureau
March 10, 2026
0
SEI Engages IBM to Accelerate Enterprise Transformation Through Agentic AI

SEI announced it has joined forces with IBM IBM to accelerate enterprise transformation through agentic AI and automation and modernize how it operates, innovates, and delivers value to clients—reinforcing...

Read moreDetails

SailPoint redefines identity security with new adaptive identity innovations

by DigitalCIO Bureau
March 10, 2026
0
SailPoint redefines identity security with new adaptive identity innovations

New AI-powered capabilities deliver real-time governance, secure the full spectrum of human and machine identities, and provide integrated threat management for the modern enterprise SailPoint, Inc. today announced...

Read moreDetails

TCS launches Gemini Experience Center in the US to help accelerate AI-powered manufacturing

by DigitalCIO Bureau
March 9, 2026
0
TCS launches Gemini Experience Center in the US to help accelerate AI-powered manufacturing

The seventh TCS GEC globally integrates Google’s Gemini models with TCS’ manufacturing expertise to help accelerate the adoption of Physical AI and build future-ready enterprises Tata Consultancy Services...

Read moreDetails
Next Post
OpenText India Driving Innovations for Customers Globally

OpenText India Driving Innovations for Customers Globally

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Related News

Real estate tokenization firm Manifest Brings Access to $35 Trillion U.S. Property Equity Market for Indian Investors

Real estate tokenization firm Manifest Brings Access to $35 Trillion U.S. Property Equity Market for Indian Investors

May 8, 2025
Punnet Kaur Kholi Joins Liberty General Insurance as President, Information Technology & Data

Punnet Kaur Kholi Joins Liberty General Insurance as President, Information Technology & Data

September 6, 2023
Uber partners with Indian Air Force to offer mobility solutions

Uber partners with Indian Air Force to offer mobility solutions

October 18, 2024

Browse by Category

  • Acquisition
  • Appointment
  • Archive
  • Artificial Intelligence
  • CIO Interviews
  • Cloud
  • Datacenter
  • Events and Conferences
  • Market Insights
  • News
  • Opinion and Analysis
  • Products
  • Resources
  • Security
  • Storage
  • Tech News
  • Telecom
Digitalcio

Welcome to DigitalCIO, your ultimate source for staying ahead in the ever-evolving world of technology and business.

BROWSE BY TAG

Acquisition AI Appointment artificial intelligence Artificial Intelligence and Machine Learning AWS Barracuda Big Data and Analytics Blockchain CISCO Cloud Computing Cloudflare Commvault CrowdStrike Cybersecurity Digital Transformation Dynatrace E-books Fortinet Gartner GenAI Generative AI Google Cloud IBM Infographics Internet of Things (IoT) Kaspersky Microsoft NTT DATA NVIDIA Palo Alto Networks Panel Discussion Qlik Salesforce ServiceNow Sophos TCS Tenable Trend Micro Veeam Veeam Software Vertiv Webinars Whitepaper Zscaler

CATEGORIES

  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
  • Archive

NAVIGATION

  • Home
  • About Us
  • Advertise with Us
  • Contact Us

© 2024 digitalcio.in - All rights reserved.

No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources

© 2024 digitalcio.in - All rights reserved.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?