Rade Furtula, Presales Manager for Eastern Europe at Kaspersky – Caution and awareness are the best prevention from phishing attacks
Source: PR
Tuesday, 04.11.2025.
13:25
Tuesday, 04.11.2025.
13:25
(Photo: Djordje Tomić)
– Cybercriminals and attackers who launch phishing attacks already routinely use generative AI tools, deepfake technology, imitation of electronic-physical signatures and biometric data.
AI-generated emails or messages are much more personalized and convincing, without grammatical errors that could easily indicate phishing.
In addition, cybercriminals very easily create fake websites - imitations of famous brands. This allows them to target not only individual users but also business users (corporate email addresses) - as indicated by the increase in detected spam/malicious attachments in corporate mailboxes.
Phishing is increasingly evolving from mass and fairly simple fraud attempts to more sophisticated and harder to detect ones, making it challenging for both experienced users and security systems.
Caution and awareness are the best prevention from these attacks - we should get into the habit of always routinely checking the sender’s name and address and the content of the message - even if the sender looks legitimate, but the message requests some unusual activity, check via an alternative channel (e.g. by phone).
It is also necessary to pay attention to the URL addresses of the websites we visit: possible letter substitutions (“0” instead of “O”, “1” instead of “I”) can indicate a fake page.
A regularly updated reliable security solution that has the ability to recognize and block phishing campaigns, as well as regular, high-quality education of users and employees can also help us in this activity: regular training and simulations of phishing attacks reduce the likelihood of a successful attack.
What is at the top of the list of sophisticated attacks in the field of information security?
– Traditionally, the most sophisticated attacks are those launched by well-organized APT groups that use so-called zero-day vulnerabilities in popular programs or backdoor modules for espionage.
In the first case, these are flaws in the program itself, application or operating system that cybercriminals discover even before the official use of that version of the program has begun, which means that there is not even a “patch” for such vulnerabilities yet.
Our experts have discovered more than 30 such vulnerabilities for some of the most famous software solutions in the past 10 years.
When we talk about backdoor modules - we are talking about an unknown weakness in the code that allows cybercriminals unauthorized access to private data and they are usually very difficult to detect.
Sophisticated attacks are usually not massive - they are targeted at operational technology (OT) and industrial control systems (ICS) infrastructures - e.g. biometrics, automation systems, the power sector.
In the first quarter of this year, we registered and blocked attacks on more than a fifth (21.9%) of ICS computers. They are also popular for so-called supply-chain attacks, when attackers compromise a supplier/partner to reach the ultimate victims, which makes detection more difficult and increases the reach.
Which countries and industries are most “under attack?”
– Traditionally, cybercriminals target industries that they believe will bring them the greatest financial benefits, such as financial services and banking. In addition, critical infrastructure (energy, oil and gas), telecommunications, government and defense are also of constant interest.
If we talk about geography, it is important to understand that the most sophisticated attacks follow geopolitical conflicts and actors, but there is no country or individual that will not be of interest to some cybercriminals - whether the goal of their attack is material gain, or confidential or private information that cybercriminals can easily cash in on the black market.
When we talk about advanced security systems, what do we mean?
– By this term, we mean a combination of technologies, processes and strategies that go beyond the basic, traditional antivirus and firewall approach.
So - continuous network monitoring and advanced endpoint device protection that not only detects known threats, but also uses behavioral detection (“Behavior Detection”), activity analysis, rollback functions (“System Watcher / Rollback”) that can undo the damage caused by malware.
(Photo: Djordje Tomić)
When it comes to the approach of the organizations themselves, advanced systems also include network segmentation, application access control (whitelisting/blacklisting), Patch Management and data encryption on endpoint devices and, what’s mandatory: staff education, attack simulations and integrated incident-response processes that are predefined in the organization.
In short: advanced protection means having multiple layers, active detection, rapid response capabilities, and specialized tools for specific types of networks (IT + OT).
Experts say that once an incident occurs, digital forensics is important. Explain what it entails?
– I would agree with that opinion - forensics implies that it is not enough to just “come and fix it,” but rather to thoroughly understand the attack in order to improve protection and reduce risk.
In practice, this means applying technical, analytical, and procedural methods to determine exactly what happened, how and when, and which systems were affected. It also involves analyzing the malware and the elements of the attack: how the malware entered the system (e.g. through a phishing link, a vulnerability), which modules it controlled, what data it exfiltrated or modified.
All this is necessary to determine the scope of the incident: which systems were compromised, what the dwell time was, whether the data was exposed, whether encryption was performed, what privileges were gained by malicious actors.
Forensic analysis, in addition to regulatory and legal procedures, also helps in restoring the system to function, and often provides recommendations for security measures and changes in processes in order to prevent future incidents.
Data protection is always one of the most important items. How to prevent data theft, what are the data recovery systems and what about backups?
– Data protection also includes preventing data loss or unauthorized access, as well as the ability to recover in the event of an incident.
What is very important is that companies adapt protection to their specific needs and IT infrastructure, but some of the universal rules are:
– Application of least privilege: users and services should only have necessary access to data.
– Data and network segmentation: critical data must not be accessible from the public or less protected part of the network.
– Data encryption at rest and in transit: so that in case the data is “stolen,” it is not readable without the key.
– Access control and multi-factor authentication (MFA) for access to critical information and systems.
– Monitoring and detection of access anomalies: when someone accesses or exfiltrates data without authorization, you need to react quickly.
– Protecting endpoint devices and networks so that malware does not enter the system and enable data exfiltration (e.g. through a backdoor).
– Employee education: many incidents begin with human error (clicking on a link, opening attachments sent with e-mail, sending data via unprotected channels).
In addition, a basic prerequisite for security is regular backups of key data and systems - ideally in multiple locations (on-site, off-site, cloud) with regular testing of the information recovery procedure - a backup is only useful if you can quickly and successfully restore it.
Through an integrated data protection strategy, regular backups and a defined recovery process, you can reduce the financial and reputational risk that comes with data theft or loss.
Companies:
Kaspersky
Tags:
Kaspersky
Rade Furtula
phishing
cyber crime
data protection
financial services
banking
malware
Comments
Your comment
Most Important News
Full information is available only to commercial users-subscribers and it is necessary to log in.
Pratite na našem portalu vesti, tendere, investicione projekte, grantove i pravnu regulativu.
Registracija na eKapiji vam omogućava pristup potpunim informacijama i dnevnom biltenu
Naš dnevni ekonomski bilten će stizati na vašu mejl adresu krajem svakog radnog dana. Bilteni su personalizovani prema interesovanjima svakog korisnika zasebno,
uz konsultacije sa našim ekspertima.

Izdanje Srbija
Serbische Ausgabe
Izdanje BiH
Izdanje Crna Gora