enterprisesecuritymag

Enterprise Security Magazine

Cofense
Bolstering the Corporate Defences against Phishing

It was an ordinary workday for a healthcare company until the employees received an email from their CEO. The email was not a typical meeting invite or query. Rather, the email simply asked them to read and agree to company policy. When they clicked on the agree button, it took them to a login page, where it requested them to enter their employee credentials. While the email sounded quite authentic, some well-trained employees looked at the message carefully. Fortunately, the company had already conditioned its workforce to spot phishing attacks using Cofense PhishMe. The employees reported the suspicious email through the Cofense Reporter plug-in embedded in their email. The analysts at Cofense identified the email to be malicious and quickly alerted the healthcare company, thus thwarting the attempt of the threat actor to harvest employee credentials.

“Threat actors today are upgrading their tactics at a very rapid pace, and vendors of perimeter controls and security gateways can barely keep up with this change,” says David Janson, Vice President of International Sales at Cofense. To help organisations bolster their cybersecurity defences and counter phishing attacks, Cofense offers an end-to-end portfolio of robust cybersecurity solutions, spanning threat awareness to detection, analysis and mitigation. To this extent, Cofense PhishMe leverages experiential learning— simulations of real phishing threats that have slipped past secure email gateways—to bolster employee awareness about the latest phishing campaigns and tactics used by attackers, thus empowering end users to proactively spot suspicious emails.

However, defence against phishing does not stop at mere awareness of a threat. Cofense Reporter, therefore, allows users to notify security teams of suspicious messages with a single click. These user reported emails are then analysed by the Cofense Triage platform, accelerating phishing investigation and response by surfacing real threats so security analysts can quickly cut through the noise of hundreds to thousands of daily reported emails and prioritise where they focus their energy. The malicious emails, including those that went unreported, are then automatically quarantined by Cofense Vision in minutes, facilitating a robust phishing defence across the organisation.

Cofense brings a unique approach in its fight against phishing.

Artificial intelligence and automation are insufficient in detecting and thwarting phishing campaigns. Cofense, therefore, adds a layer of human intelligence to accelerate email analysis at scale and fill the gap left by ineffective secure email gateways. Leveraging the intuitive solutions provided by Cofense, organisations can empower their employees to be an integral part of their cyber defence. As a result, even if the perimeter solutions fail to detect such malicious emails, users can identify suspicious messages, transforming vulnerable targets into an essential layer of defence. “Our end-to-end phishing defence solutions combine cutting-edge technology with human vetting to provide intuition and insights that machines or technology alone can’t deliver,” underscores Janson.

Our end-to-end phishing defence solutions combine cutting-edge technology with human vetting providing intuition and insights that machines or technology alone can’t deliver


As Janson also highlights, modern phishing attacks are increasingly polymorphic with each passing day. He explains, “If 100 phishing emails are delivered to 100 different users, each of the emails might have several unique elements to it.” It is therefore challenging to identify a phishing email quickly, especially when time is of great importance and seconds count. To enhance the response capability of clients, Cofense designed a robust solution, Cofense Intelligence, which underpins Cofense’s portfolio. Cofense Intelligence equips organisations with relevant information and insights about emerging threats detected in the wild, enabling security teams to defend their organisations against the attacks before they hit.

The most prevalent motive of phishers is credential harvesting, allowing threat actors to steal valuable log-in details to access the corporate network. Especially with the COVID-19 pandemic and a newly remote workforce, threat actors are extensively exploiting the uncertainty, confusion and fears shared by many across the globe. An analysis by Cofense’s Phishing Defence Centre (PDC) shows there has been a significant uptick in phishing attacks. The rate of COVID-19 related phishing attacks, notably, has increased from just one percent to more than seven percent in less than a month. In such a precarious landscape, Cofense has established a Coronavirus phishing info centre microsite to deliver accurate information and help protect organisations from threat actors. Every day, Cofense posts the latest COVID-19 phishing emails and tactics that successfully evaded detection by email gateways as well necessary rules that will help organisations proactively identify signs of any exploits to defend against intrusion,. The resources are not only free but are also updated regularly to continue identification of new threats.

Driven by such user-centric approaches, Cofense is fast expanding its presence in the cybersecurity space. “Cofense is all about empowering organisations to quickly detect, analyse, and quarantine the phishing attacks before they can cause significant damage to their business and workflow,” concludes Janson.

Company
Cofense

Headquarters
Leesburg, VA

Management
Rohyt Belani, Co-Founder & CEO and Aaron Higbee, Co-Founder & CTO

Description
Cofense®, the leading provider of intelligent phishing defence solutions worldwide, is uniting humanity against phishing. The Cofense suite of products combines timely attack intelligence on phishing threats that have evaded perimeter controls and were reported by employees, with best-in-class security operations technologies to stop attacks faster and stay ahead of breaches. Cofense customers include Global 1000 organizations in defence, energy, financial services, healthcare and manufacturing sectors that understand how changing user behaviour will improve security, aid incident response and reduce the risk of compromise

Cofense News

Are DarkGate and PikaBot the new QakBot?

A malware phishing campaign that began spreading DarkGate malware in September of this year has evolved to become one of the most advanced phishing campaigns active in the threat landscape. Since then, the campaign has changed to use evasive tactics and anti-analysis techniques to continue distributing DarkGate, and more recently, PikaBot. The campaign surged just one month after the last seen QakBot activity, and follows the same trends used by the infamous threat actors that deploy the QakBot malware and botnet. This campaign disseminates a high volume of emails to a wide range of industries, and due to the loader capabilities of the malware delivered, targets can be at risk of more sophisticated threats like reconnaissance malware and ransomware.

In August of this year, the FBI and the Justice Department announced that they had disabled the QakBot infrastructure. Since then, QakBot has remained silent, with no significant activity seen from the malware infrastructure. While direct attribution between the QakBot threat actors and this campaign can be difficult, we can show the similarities between the two. Starting with the timeline of the campaign, Cofense Intelligence last reported on QakBot towards the end of June whereas DarkGate reports first emerged during July. The new campaign that is delivering DarkGate and PikaBot follows the same tactics that have been used in QakBot phishing campaigns. These include hijacked email threads as the initial infection, URLs with unique patterns that limit user access, and an infection chain nearly identical to what we have seen with QakBot delivery. The malware families used also follow suit to what we would expect QakBot affiliates to use. Along with many other capabilities, both malware families can act as loaders with the ability to add additional malicious payloads to unknown infected machines.

Inside Look at the Phishing Campaign

This campaign is undoubtedly a high-level threat due to the tactics, techniques, and procedures (TTPs) that enable the phishing emails to reach intended targets as well as the advanced capabilities of the malware being delivered. During the lifespan of the campaign, we have noticed several different infection chains, almost as if the threat actors were testing different malware delivery options. However, a favored infection chain to deliver the malware has been made apparent and is illustrated in Figure 2. This infection chain follows in line with that seen in QakBot campaigns during May of this year (Active Threat Reports (ATRs): 325113, 324360, 323510).

The campaign begins with a hijacked email thread to bait users into interacting with a URL that has added layers that limit access to the malicious payload only to users that meet specific requirements set by the threat actors (location and internet browser). This URL downloads a ZIP archive that contains a JS file that is a JS Dropper, which is a JavaScript application used to reach out to another URL to download and run malware. At this stage, a user has been successfully infected with either the DarkGate or PikaBot malware.

DarkGate and PikaBot are both considered advanced malware with loader capabilities and anti-analysis behavior. This is attributed to the advanced features that each family offers and the steps within each malware config that make analysis more complex for malware researchers. Most notable, and what would be the most appealing to threat actors like the QakBot affiliates, is that both malware families can deliver additional payloads once successfully planted on a user’s machine. A successful DarkGate or PikaBot infection could lead to the delivery of advanced crypto mining software, reconnaissance tools, ransomware, or any other malicious file the threat actors wish to install on a victim’s machine. More details on the individual families can be found below:

• DarkGate was first seen in 2018 and is capable of cryptocurrency mining, credential theft, ransomware, and remote access. The capabilities outlined do not come default installed but must instead be executed similarly to plugins. It has multiple methods of avoiding detection and two distinct methods of escalating privileges. DarkGate makes use of legitimate AutoIT files and typically runs multiple AutoIT scripts.

• PikaBot is a new malware family first seen in 2023. It is classified as a loader due to its ability to deliver additional malware payloads. It contains several evasive techniques to avoid sandboxes, virtual machines, and other debugging techniques. It has been observed to exclude infecting machines in CIS (Commonwealth of Independent States) countries. These countries were all members of the former Soviet Union.

Evasive Phishing Tactics Combined with Anti-analysis Techniques

This campaign combines well-known evasive phishing tactics with techniques known to disrupt malware analysis processes. The first steps of this campaign are far more complicated than the average phishing attack. The threat actors disseminate the phishing emails through hijacked email threads that may be obtained from Microsoft ProxyLogon attacks (CVE-2021-26855). This is a vulnerability on the Microsoft Exchange Server that allows threat actors to bypass authentication and impersonate admins.

Responding to email threads creates an added layer of trust between the threat actors and the target, since the target may recognize the conversation and believe the sender to be trusted. Figure 3 (ATR 351964) below is a real phishing example that reached an enterprise user’s inbox. The threat actors provided a message relevant to the hijacked thread to the target with the inclusion of a malicious link. This is one of the many factors that give campaigns that utilize this tactic a higher chance of success.

Experimenting with Malware Delivery Options

The most common delivery mechanism seen in this campaign is JS Droppers, however, Cofense Intelligence has been tracking this campaign since the beginning and has documented each infection chain utilized in this campaign. The most notable, outside of the JS Droppers, include the use of Excel-DNA Loader, VBS Downloaders, and LNK Downloaders. Threat actors use these methods for downloading and installing their malware every day so it’s not uncommon to see a campaign this advanced incorporate these additional methods within the infection chains. The most unusual method would be the incorporation of the Excel-DNA Loaders. This is a relatively new delivery mechanism (first seen in 2021) that became very popular early on and incorporates the use of Microsoft Excel add-ins to download and run malicious payloads.

• JavaScript Dropper (JS Dropper) is a script application written using a Microsoft ECMAScript dialect known as Jscript, commonly referred to as JavaScript. These files can be identified by the file extension JS and can allow threat actors to create a malware delivery tool that is both natively executable on the Windows platform and highly malleable and adaptable. In most cases, these files are used to download, write to disk, and run a Windows PE executable or DLL payload.

• Excel-DNA Loader (Excel DotNET for Applications) is an open-source project that is used for creating XLL files as add-ins for Microsoft Excel. An XLL file is a Microsoft Excel add-in that can have many legitimate workplace uses, but threat actors have taken these add-ins and configured their files to reach out to payload locations to download and run malicious payloads. This method of delivering malware was first observed in 2021 delivering a wide range of malware, most notable was the Dridex banking trojan.

• VBS Downloaders leverage Visual Basic runtime applications, usually available within Windows environments, to carry out the download and execution of malware binaries. These scripts use the file extension VBS and run through Microsoft Office products or invoke Windows executable applications, like cscript.exe or wscript.exe, from the command line.

• LNK Downloader is a Microsoft LNK shortcut downloader that abuses the trusted nature of being a “safe” file format to secure entry to a victim’s computer before downloading and executing a malware payload. These files, known by the LNK extension, play the role of a file shortcut in Windows Explorer. However, threat actors have repurposed them to make a reference to their own content in such a way that allows executable script elements to run within the Windows environment.

This campaign is advanced, well-crafted, and has already evolved since it was first seen in the wild. The threat actors behind the campaign maintain skills beyond the average phisher, and employees should be aware that this type of threat exists. Cofense Intelligence will continue to monitor the changes and the strong similarities to QakBot that this campaign exhibits.

Cofense Adds Email Security Risk Management and Validation Reporting to PhishMe®

The New Employee Engagement Index empowers employees; making them security allies, not liabilities.

LEESBURG -Cofense®, the leader in email threat detection and response solutions, today unveiled new enhancements to its PhishMe® Employee Security Awareness Training (SAT) Platform. The latest addition, Employee Engagement Index, is set to transform how organizations manage email security risks.

The introduction of the Employee Engagement Index (EEI) transforms employees into security allies. This innovative tool continuously monitors employee interactions with PhishMe simulations, providing real-time data that offers valuable insights into their readiness to combat phishing threats, before they become damaging to an organization’s revenue and reputation.

"Cofense PhishMe pioneered the SAT industry over a decade ago, and in 2024, we proudly delivered our one-billionth employee training simulation," stated David Van Allen, CEO of Cofense. "Our experience and data confirm that employees are an organization's strongest asset against email based cyberattacks; they should not be considered the risk. That’s the core reason why we have upgraded PhishMe with the Employee Engagement Index."

It is a well-known fact that most successful cyberattacks on businesses begin with a phishing email that slips past existing email security measures, even those new measures using AI. This makes employee email security awareness programs a critical component of a comprehensive, layered defense strategy. When employees are properly trained and motivated, they become a formidable first line of defense.

PhishMe’s Employee Engagement Index leverages over a decade of Cofense curated threat intelligence and combines those data with current employee behavioral patterns. The EEI then generates a continuously updated proficiency score, displaying a personalized metric that assesses individuals, cohorts, groups, and departments, allowing organizations to quickly pinpoint areas needing improvement and allows for immediate, targeted remediation efforts.

Employee Engagement Index Benefits:

• User-Level Metrics: Identifies engagement and resilience gaps across all employee levels, ensuring targeted reinforcement programs strengthen the organization's cybersecurity posture.

• Reporting Rate: Provides reporting of employees’ identification and activity around phishing attempts, indicating awareness and responsiveness of the first line team.

• Susceptibility Rate: Identifies employees or cohorts who are prone to phishing, enabling more targeted reinforcement and remediation.

• Proficiency Score: Highlights individuals’ ability to accurately recognize and report phishing.

• Leaderboard View: Ranks employees by resilience, identifying top performers and those requiring additional support.

© 2026 Enterprise Security Magazine. All rights reserved. Headquartered in Fort Lauderdale, FL, USA.