{"id":10843,"date":"2019-05-20T17:02:44","date_gmt":"2019-05-20T21:02:44","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=10843"},"modified":"2023-04-07T14:00:47","modified_gmt":"2023-04-07T18:00:47","slug":"58-of-phishing-websites-now-use-https","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/58-of-phishing-websites-now-use-https\/","title":{"rendered":"58% of Phishing Websites Now Use HTTPS"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"h-phishing-saw-a-sharp-increase-in-q1-2019-again\">Phishing saw a sharp increase in Q1 2019\u2026 again.<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Stop me if you\u2019ve heard this one before: incidence of\nphishing have increased since last quarter. Again. Just like the quarter before\nthat. And the quarter before that. Dating all the way back to the days of the\nearly internet when a down-on-his-luck Nigerian prince first sought financial\nrelief from the well-to-do denizens of AOL and Hotmail. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Nowadays phishing has evolved. Substantially. These are no longer shot-in-the-dark style emails that somehow manage to elude your spam folder. These are now highly-tailored feats of social engineering that target specific industries, companies and individuals. Phishing, the simple act of ripping someone off with a grammatically questionable email has grown up into CEO fraud, whaling, spearphishing, etc. It\u2019s become the most common delivery mechanism for malware and other cyber attacks. <a href=\"https:\/\/www.thesslstore.com\/blog\/hospital-employees-open-1-out-of-every-7-phishing-emails\/\">91% of cyber attacks now start with a phishing email<\/a>. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In many ways phishing is like a gateway hack. It starts off as\njust a few innocent spearphishing emails among friends, but before you know it,\nyou\u2019re huddled over a laptop in an Eastern European internet caf\u00e9 trying to\nscrape together enough of a botnet to launch one more DDoS\u2026 <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2026anyway, according to the Anti-Phishing Working Group (APWG) <a href=\"https:\/\/businessinsights.bitdefender.com\/phishing-attacks-against-saas-webmail-services-rise-sharply-in-q1\">phishing is up again in Q1 2019<\/a> and nearly 60% of the phishing websites the study turned up were using SSL\/TLS \u2013 <a href=\"https:\/\/www.thesslstore.com\/blog\/is-the-green-padlock-dead\/\">sporting the green HTTPS padlock<\/a>. So, today we\u2019re going to take a look at the study, break down some of the trends and offer a little insight on shoring up those defenses.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s hash it out.<span id=\"newline\"><\/span><\/p>\n\n\n<span style=\"--tl-form-height-m:140.667px;--tl-form-height-t:118.1042px;--tl-form-height-d:118.1042px;\" class=\"tl-placeholder-f-type-shortcode_12779 tl-preload-form\"><span><\/span><\/span>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-phishing-in-q1-2019-the-big-takeaways\">Phishing in Q1 2019: The big takeaways<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The APWG is a non-profit industry association that was founded in 2003. Its membership comprises over 2,000 organizations across the world. It publishes quarterly reports on phishing that look at the industries targeted, total number of phishing emails received and how many new phishing websites have been created over the last three months. Keep in mind, these are not global figures &#8211; this only pertains to the cases and campaigns that were reported to the APWG.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For Q1 of 2019, the APWG came away with three major takeaways (actually, four \u2013 we just aren\u2019t going to focus on the case study in Brazil). We\u2019ll mention them here really quickly and then drill down into the HTTPS phishing issue &#8211; given that it&#8217;s especially relevant to us.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Key takeaways:<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright\"><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"277\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/Most-Targeted-Industries-300x277.png\" alt=\"Most targeted industries by phishing\" class=\"wp-image-10847\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/Most-Targeted-Industries-300x277.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/Most-Targeted-Industries.png 569w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/figure>\n<\/div>\n\n\n<ul class=\"wp-block-list\">\n<li>SSL\/TLS certificates are still being widely used\nby phishing websites, aided by free offerings from CAs like Let\u2019s Encrypt, and hosting\ncompanies like cPanel. 58% of phishing websites are now served via HTTPS.<\/li>\n\n\n\n<li>The total number of phishing websites increased\nsubstantially over Q3 and Q4 of 2018, likewise the number of phishing websites\nincreased in each month so far in 2019, peaking in March \u2013 the final month of\nthe quarter.<\/li>\n\n\n\n<li>Phishing targeted Software-as-a-Service and\nWebmail clients the most over the first quarter of 2019. This is the first time\nthat segment has appeared ahead of the payment industry since the APWG has been\ndoing the study.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-58-of-phishing-websites-now-use-ssl-tls-https\">58% of Phishing Websites now use SSL\/TLS &amp; HTTPS<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">We\u2019ve been raising the flag for a few years now on <a href=\"https:\/\/www.thesslstore.com\/blog\/browsers-helping-https-phishing\/\">HTTPS phishing<\/a>. Admittedly, things have gotten a lot better thanks to the browsers \u2013 specifically Google \u2013 <a href=\"https:\/\/www.thesslstore.com\/blog\/google-will-remove-the-secure-indicator-in-september\/\">deprecating the \u201cSecure\u201d visual indicator<\/a> that was appearing anytime a website used HTTPS.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This was exceedingly dangerous because it allowed phishing websites to display a Google-given icon that proclaimed they were secure. People conflate secure and safe. <a href=\"https:\/\/www.thesslstore.com\/blog\/1-4-million-new-phishing-websites-created-every-month\/\">Phishing exploded<\/a>. It was a problem.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Now Google has gone the other way and started to deprecate HTTPS visual indicators all together, claiming that asking the user to glance at the address bar to make some kind of a security decision is \u201cuser hostile.\u201d I would ask how <a href=\"https:\/\/www.thesslstore.com\/blog\/google-and-facebook-manipulate-users-to-circumvent-gdpr\/\">burying peoples\u2019 privacy preferences in your settings menu<\/a> is any less \u201c<a href=\"https:\/\/www.thesslstore.com\/blog\/google-fined-57000000-for-gdpr-violations\/\">user hostile<\/a>,\u201d but let\u2019s not split hairs. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Regardless, HTTPS phishing is a major problem for the internet as a whole and this industry specifically. However, given that CAs <a href=\"https:\/\/www.thesslstore.com\/blog\/lets-encrypt-phishing\/\">aren\u2019t supposed to be in the business of policing content<\/a>, there\u2019s not a whole lot else to be done. Bad guys can get encryption, too. Well, at least DV SSL encryption. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Because I don&#8217;t want to say this entire trend can be attributed to free DV SSL certificates, but&#8230; this entire trend can be attributed to free DV SSL certificates. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is why many SMBs and Enterprises have shifted to Organization Validation and Extended Validation SSL certificates. DV SSL doesn&#8217;t assert any organizational identity, it just verifies a domain name. By asserting identity with an SSL\/TLS certificate organizations can help their customers avoid being phished and can ensure their employees aren&#8217;t duped by spoofed websites. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Still, HTTPS phishing has shifted from just being a\nstartlingly large minority into \u2013 what is becoming \u2013 a highly prevalent tactic.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"900\" height=\"525\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/Phishing-by-Year.png\" alt=\"HTTPS phishing by year\" class=\"wp-image-10846\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/Phishing-by-Year.png 900w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/Phishing-by-Year-300x175.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/Phishing-by-Year-768x448.png 768w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/figure>\n<\/div>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-websites-i-thought-we-were-talking-about-email\">Websites? I thought we were talking about email\u2026<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Oftentimes the phishing email is just phase one of a much\nlarger campaign. The email is designed to get the target to take the intended\naction. That could be something as simple as opening an attachment, or it could\ninclude following a link to a phishing website. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">While occasionally you\u2019ll see a watering hole-style phishing site that is just set up to take advantage of anyone unfortunate enough to navigate to it, most of these pages are designed only to be found via the links they generate and put in phishing emails. There\u2019s a couple of main reasons for this:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One, you would never get these phishing websites to rank well enough to see any kind of results. SEO is a massive industry, it takes months and years to get results. Phishers don\u2019t have that kind of time. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The second reason, and the more immediate one, is that Google and various other blacklists and watch dogs are actively seeking out phishing websites so they can block them and protect internet users. That\u2019s why these pages are hidden, de-indexed, and hopefully kept away from the prying eyes of Google.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In fact, most of these phishing sites have a shelf life of\njust a few hours.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright\"><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"295\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/Phishing-Sites-Found-300x295.png\" alt=\"Phishing sites found in the first three months of 2019\" class=\"wp-image-10848\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/Phishing-Sites-Found-300x295.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/Phishing-Sites-Found.png 533w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">That being said, while they can\u2019t all be winners (just like we can\u2019t all be astronauts), some of these pages show an impressive level of detail, even going so far as to mimic social buttons, site seals and trust indicators. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One indicator they have not historically been able to manipulate though \u2013 at least not easily \u2013 was the green padlock icon that was associated with HTTPS. It hasn\u2019t always been the most effective, but internet users have been trained to look for that padlock. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Unfortunately, phishers don\u2019t keep very good statistics. There is no NetCraft for phishing where you can track success rates across industries and campaigns. It would be nice, but that level of transparency is rarely seen from criminals.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But, given the steady rise in the percentage of phishing websites that we\u2019ve seen over the past few years, I think it would suffice to say HTTPS phishing works better than non-HTTPS phishing.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And here\u2019s the thing, it would be na\u00efve to think that an SSL\/TLS certificate itself improves the viability of a phishing campaign. There needs to be a lot of other things that have to go right to achieve the desired results. Other brush strokes on the canvas. But when paired with all the other little touches that make a phishing site feel believable, that green padlock and HTTPS can be just enough to confirm someone\u2019s errant impressions. The perfect final touch.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That&#8217;s why once you get to that website, all bets are off.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, it\u2019s best to prevent it from ever getting past that first email. <\/p>\n\n\n<span style=\"--tl-form-height-m:140.667px;--tl-form-height-t:118.1042px;--tl-form-height-d:118.1042px;\" class=\"tl-placeholder-f-type-shortcode_12779 tl-preload-form\"><span><\/span><\/span>\n\n\n<p class=\"wp-block-paragraph\"><em>As always, leave any\ncomments or questions below\u2026<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Nearly 3 out of every 5 phishing sites now uses HTTPS and SSL\/TLS encryption. The only answer is to stop things from ever getting that far with good email security.<\/p>\n","protected":false},"author":6,"featured_media":10844,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[130],"tags":[170,10373,166],"class_list":["post-10843","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-everything-encryption","tag-https","tag-https-phishing","tag-phishing","post-with-tags"],"views":23966,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/05\/HTTPS-Phishing-Feature.png","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/10843","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=10843"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/10843\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/10844"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=10843"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=10843"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=10843"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}