TecnoArtesanos Tech BlogTecnoArtesanos Tech Blog

Blog

0
admin
Wednesday, 19 February 2025 / Published in Uncategorized

Darktrace: 96% of Phishing Attacks in 2024 Exploited Trusted Domains Including SharePoint & Zoom Docs

Threat actors are increasingly targeting trusted business platforms such as Dropbox, SharePoint, and QuickBooks in their phishing email campaigns and leveraging legitimate domains to bypass security measures, a new report released today has found. By embedding sender addresses or payload links within legitimate domains, attackers evade traditional detection methods and deceive unsuspecting users.

Contents
  • Legitimate enterprise services hijacked for most phishing campaigns in 2024
  • Phishing attacks surge with AI-generated tactics
    • Must-read security coverage
  • Living-off-the-land techniques: A growing security threat
  • Ransomware groups exploit enterprise tools for stealth attacks

According to Darktrace’s Annual Threat Report 2024, the authors detected more than 30.4 million phishing emails, reinforcing phishing as the preferred attack technique.

Legitimate enterprise services hijacked for most phishing campaigns in 2024

Darktrace noted cybercriminals are exploiting third-party enterprise services, including Zoom Docs, HelloSign, Adobe, and Microsoft SharePoint. In 2024, 96% of phishing emails utilised existing domains rather than registering new ones, making them hard to detect.

Patrocinado por TecnoArtesanos ¿Tu empresa ya está usando IA? Automatizamos procesos, integramos asistentes inteligentes y conectamos tus sistemas. Descubre cómo →

Attackers were observed using redirects via legitimate services, such as Google, to deliver malicious payloads. In the case of the Dropbox attack, the email contained a link leading to a Dropbox-hosted PDF with an embedded malicious URL.

SEE: How business email compromise attacks emulate legitimate web services to lure clicks

Alternatively, threat actors abused hijacked email accounts, including those from Amazon Simple Email Service, belonging to business partners, vendors, and other trusted third-parties. The report’s authors say this “highlight(s) that identity continues to be an expensive problem across the estate and a persistent source of pain across enterprise and business networks.”

Phishing attacks surge with AI-generated tactics

Among the phishing emails that Darktrace found:

  • 2.7 million contained multistage malicious payloads.
  • More than 940,000 contained malicious QR codes.

The sophistication of phishing attempts continues to rise, with spear phishing — highly-targeted email attacks — making up 38% of cases. Meanwhile, 32% use novel social engineering techniques such as AI-generated text with linguistic complexity. This complexity might manifest as increased text volume, punctuation, or sentence length.

Darktrace collated insights from its more than 10,000 global customers for its Annual Threat Report 2024, leveraging self-learning AI, anomaly-based detection, and thorough analysis from its threat research team.

Must-read security coverage

Living-off-the-land techniques: A growing security threat

Another attack method involves initial network breaches via vulnerabilities in edge, perimeter or internet-facing devices, followed by living-off-the-land techniques or LOTL.This strategy exploits pre-installed, legitimate enterprise tools to execute malicious activities while avoiding detection.

Darktrace found that 40% of identified campaign activity in early 2024 involved the exploitation of internet-facing devices, including from Ivanti Connect Secure, Ivanti Policy Secure, Palo Alto Network, and Fortinet. Attackers favor LOTL techniques because they eliminate the need for custom malware and reduce the risk of triggering traditional security alerts.

On top of exploiting vulnerabilities in these edge devices, threat actors are increasingly using stolen credentials to log into remote network access solutions like VPNs for initial network access, before leveraging LOTL techniques.

Ransomware groups exploit enterprise tools for stealth attacks

Ransomware groups — including Akira, RansomHub, Black Basta, Fog, and Qilin, along with emerging actors Lynx — have increasingly been using legitimate enterprise software. Darktrace has observed these groups using:

  • AnyDesk and Atera to mask command-and-control communications.
  • Data exfiltration to cloud storage services.
  • File-transfer technology for rapid exploitation and double extortion.

SEE: Most Ransomware Attacks Occur When Security Staff Are Asleep, Study Finds

These groups are also frequently recruited for Ransomware-as-a-Service or Malware-as-a-Service, with the use of MaaS tools increasing by 17% from the first to the second half of 2024. Use of Remote Access Trojans, malware which allows an attacker to remotely control an infected device, also increased by 34% over the same period.

¿Quieres aplicar esto en tu empresa?

En TecnoArtesanos desarrollamos software, integramos IA y creamos experiencias digitales para negocios que quieren crecer.

Conversemos Nuestros servicios

¿Te gustó este artículo? Síguenos en Facebook para más contenido como este.

What you can read next

Redes sociales y videojuegos exponen a 20 millones de adolescentes al abuso sexual, advierte UNICEF
Conseguir inteligencia artificial general puede acabar con la relación entre OpenAI y Microsoft
Nvidia ya no quiere vender solo GPUs: quiere controlar cada chip que mueve la IA

Tecnología hecha a mano para tu negocio

Software, IA, sitios web y diseño. Hablemos de tu proyecto.

¿Hablamos? Síguenos en Facebook →

Recent Posts

  • ¿Qué es la computación confidencial? Un experto de Intel respondió nuestras dudas
  • Google abre su detector de contenido generado con IA a todo el público
  • Pusieron a GPT, Claude y Grok al volante de un Toyota Corolla. Solo uno superó la prueba
  • ChatGPT ya no responde solo con texto: ahora genera herramientas a la medida
  • ¿Adiós al efectivo? Qué propone y por qué preocupa la nueva ley de pagos digitales en México

Recent Comments

  1. A WordPress Commenter on Welcome to My Tech Blog – A New Chapter in Innovation

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • August 2016

Categories

  • Uncategorized

Recent Posts

  • ¿Qué es la computación confidencial? Un experto de Intel respondió nuestras dudas

    También abre la puerta a una forma nueva de col...
  • Google abre su detector de contenido generado con IA a todo el público

    Ahora será más fácil para todo el mundo descubr...
  • Pusieron a GPT, Claude y Grok al volante de un Toyota Corolla. Solo uno superó la prueba

    Aditya Ramabadran, Simon Mahns y Tobias Gessler...
  • ChatGPT ya no responde solo con texto: ahora genera herramientas a la medida

    Cuando le preguntas algo a un chatbot, con frec...
  • ¿Adiós al efectivo? Qué propone y por qué preocupa la nueva ley de pagos digitales en México

    La Cámara de Diputados aprobó en lo general y e...

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • August 2016

Categories

  • Uncategorized
TOP
TecnoArtesanos

Un estudio boutique que crea experiencias digitales: desarrollo de software, inteligencia artificial y soluciones en la nube, con el cuidado de la joyería fina.

¿Hablamos?

Servicios

  • Desarrollo de software
  • Integración de IA
  • Experiencias digitales
  • Redes sociales y diseño

TecnoArtesanos

  • Inicio
  • Portafolio
  • Nosotros
  • Blog

Contacto

  • +506 8730-7941
  • [email protected]
  • WhatsApp
  • Facebook
© 2026 TecnoArtesanos. Todos los derechos reservados. tecnoartesanos.com
TecnoArtesanos — Software a la medida, IA y sitios web para tu negocio. Conoce nuestros servicios →
✦ TecnoArtesanos

¿Te interesa llevar esto a tu negocio?

Escribimos sobre tecnología porque la construimos. Si tienes un proyecto en mente, conversemos: la primera llamada no tiene costo.

  • Desarrollo de software a la medida
  • Integración de inteligencia artificial
  • Sitios web y experiencias digitales
  • Redes sociales y diseño gráfico
¿Hablamos? Ver servicios

¿Prefieres WhatsApp? +506 8730-7941 · Síguenos en Facebook