Cyber Security News

Hackers Employ New Evasion Mechanisms to Bypass Security Solutions

The digital landscape, once a serene meadow, has morphed into a battleground where attackers and security vendors engage in a perpetual arms race. 

As defenses become more sophisticated, attackers adapt, devising ingenious evasion techniques to bypass security products and inflict harm. 

One such tactic, recently uncovered by Trellix Email Security, leverages the foundation of security – caching – to weave a web of deceit and compromise unsuspecting users.

Diverse tools in an attacker’s arsenal:

  • Geofencing: Malicious content masquerades as benign in specific regions, evading detection elsewhere.
  • Captcha Bypass: Automated mechanisms circumvent captchas, hindering URL payload analysis.
  • IP Evasion: Blacklisted IPs shield attackers from scrutiny, ensuring their payloads remain hidden.
  • QR Code Phishing: QR code obscurity bypasses traditional email security filters, paving the way for phishing attacks.

Cache Poisoning: A Masterclass in Deception

Trellix Email Security has unraveled a novel evasion tactic that exploits caching, a mechanism employed by security products to optimize performance. 

Caching involves temporarily storing the analysis results of URLs. Upon encountering the same URL again, the cached verdict is retrieved instead of re-performing the analysis, saving valuable resources.

This innovative attack unfolds in three distinct phases:

Phase 1: The Enticing Bait

The attack begins with an email containing a seemingly innocuous Call to Action (CTA) URL, often disguised as a OneDrive document link. This tactic capitalizes on the inherent trust associated with Microsoft’s domain.

Phase 2: The Cloaked Payload

Upon encountering the CTA URL, the security engine analyzes it and discovers a link leading to a well-established website like Google or Microsoft. Deeming it safe, the engine caches this verdict.

Phase 3: The Chameleon’s Leap

Once the URL is cached as safe, the attackers strike. They stealthily modify the seemingly harmless link within the CTA URL, redirecting it to the actual malicious payload. 

However, the cached “safe” verdict remains, allowing subsequent encounters with the CTA URL to bypass security analysis and land in the recipient’s inbox.

Understanding this intricate manipulation of caching mechanisms is crucial for effective mitigation

A Global Threat: Beyond Borders and Industries

Trellix telemetry reveals that these cache poisoning attacks are not isolated incidents. They have targeted users across diverse industries and regions, highlighting the universality of this technique.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

CISA Red Team Breaches Critical Infrastructure to Reveal SOC and Cloud Security Gaps

CISA's latest advisory for red teams warns critical infrastructure operators that security systems can fail…

5 hours ago

AI Security Startup Alice Raises $140 Million as Enterprise AI Threats Surge

Alice, the AI trust, safety, and security company formerly known as ActiveFence, has closed a…

6 hours ago

SynkLoader Mimic as IT Support Personnel Attacking Users Via Microsoft Teams

SynkLoader is using Microsoft Teams conversations to turn routine IT support requests into a route…

7 hours ago

ToxNetV2 Linux Botnet Uses NVIDIA AI to Generate Shell and Remote SSH Attack Actions

ToxNetV2 is a Linux botnet that shows how artificial intelligence can move closer to real…

7 hours ago

WhatsApp Passkeys Reach 1 Billion Users as Two-Step Verification Gets Stronger Passwords

WhatsApp has confirmed that more than 1 billion people now use passkeys to log into…

7 hours ago

ASOS Warns Customer Accounts Were Accessed Using Compromised Login Credentials

ASOS US Sales LLC reported unauthorized access to customer accounts using credentials obtained from outside…

7 hours ago