CyberSecurityNews

Phishing Powers 80% of Attacks on US Companies: How SOCs Can Detect It Early 


Phishing Powers 80% of Attacks on US Companies

Phishing remains one of the most effective ways for attackers to gain access to corporate environments. From 2013-2023, the FBI recorded 158,436 US victims of Business Email Compromise (BEC), with over $20 billion in reported losses. 

The FBI specifically warns that phishing is used to obtain corporate credentials and gain access to business networks. 

While security teams have invested heavily in email gateways, endpoint protection, and security awareness training, attackers continue to find ways around these measures. 

Modern phishing uses compromised infrastructure, legitimate services, redirect chains, dynamic pages, and sophisticated social engineering to evade traditional defenses. 

For SOC leads and CISOs, this creates a difficult operational question: How can you detect phishing early enough to stop it before it causes an incident?  

The answer begins with efficient threat intelligence. By combining fresh threat indicators with analyst-curated intelligence on active campaigns, security teams can strengthen detection, accelerate triage, and move from reacting to phishing incidents toward proactively disrupting them. 

Phishing has long posed a significant threat to US companies, but the problem has become even more challenging in recent years.  

Attackers can now create convincing phishing pages in minutes, register disposable infrastructure, abuse trusted platforms, and tailor lures to specific organizations or employees.

AI further lowers the barrier to producing realistic campaigns at scale. 

For a SOC, phishing is more than an email security problem. A single incident can lead from a malicious link to credential theft, account compromise, lateral movement, fraud, or further phishing. 

The earlier a SOC team identifies the infrastructure behind the attack, the more opportunities it has to break this chain. 

How to Proactively Combat Modern Phishing  

Many security controls still rely on reputation, known indicators, and static analysis. While useful, these approaches can miss sophisticated phishing campaigns that use new domains, legitimate redirects, and conditional phishing pages. 

By the time indicators reach conventional threat feeds, they may already be outdated or lack the context analysts need to assess them. 

For SOC leaders, the challenge is getting faster access to relevant, validated, and actionable intelligence rather than simply collecting more threat data. 

Switching to a Preventive Phishing Defense 

Threat intelligence can strengthen phishing defenses across the security workflow. It helps SOC teams detect threats earlier, investigate faster, and reduce security risks. 

Use Fresh Threat Intelligence to Detect Attacks Earlier 

One opportunity to disrupt a phishing campaign is to identify malicious infrastructure before it leads to a successful compromise.  

This requires threat intelligence that reflects recently observed threats rather than relying exclusively on indicators that may be outdated. 

ANY.RUN Threat Intelligence Feeds (TI Feeds) give SOC teams the visibility needed to spot and respond to emerging threats, from new malware to zero-day exploitation.  

ANY.RUN TI Feeds help identify and block emerging phishing threats 

TI Feeds provide fresh malicious IP addresses, domains, and URLs enriched with contextual data from Interactive Sandbox investigations conducted by more than 16,000 organizations.  

The feeds are designed to deliver 99% unique IOCs with near-zero false positives, with indicators processed to provide high-confidence intelligence from live malware and phishing investigations. 

For a SOC, this creates several practical advantages:  

  • Earlier detection: Recently discovered indicators can help identify malicious infrastructure sooner, provided the relevant infrastructure has already been observed and included in the feed.  
  • Higher-fidelity intelligence: ANY.RUN provides 99% unique, high-confidence indicators enriched with sandbox context, giving analysts greater confidence in their relevance and reducing false positives. 
  • Automation: TI Feeds can be integrated into security infrastructure through API/SDK access and standards such as STIX/TAXII.  
  • Operational response: Indicators can support detection, correlation, alerting, threat hunting, and automated blocking, delivering 58% more threats identified, 21 minutes faster MTTR, and 30% fewer Tier 2 escalations

This changes the role of threat intelligence from a resource analysts consult manually into an operational data source that can continuously feed security controls. 

Use fresh intelligence from 16K+ organizations to strengthen your phishing defenses. Explore TI Feeds for your SOC 

Give Analysts the Context They Need for Faster Triage 

Even with strong preventive controls, some phishing attempts will reach users or generate suspicious activity that requires investigation.

For example, a recent campaign used sophisticated phishing lures and adversary-in-the-middle techniques to target tens of thousands of users, primarily in the US. 

When that happens, analysts need to quickly determine whether the activity is linked to a known threat, campaign, or infrastructure and identify related indicators and techniques.

They also need to understand what to investigate, monitor, or add to existing detection coverage. 

Without sufficient context, analysts may need to search multiple sources, investigate indicators individually, and reconstruct the attack manually.

That increases investigation time and can add workload for Tier 1 and Tier 2 analysts.  

Threat intelligence reports, or TI reports, provide a broader, complementary view beyond individual indicators. 

ANY.RUN TI Reports are expert-curated research covering recent cyber threats, including malware, phishing campaigns, APT activity, and other malicious operations.  

US-focused threat analysis overviews in ANY.RUN’s TI Reports 

TI Reports can include threat overviews, targeted industries and regions, TTPs, IOCs, IOBs, IOAs, links to relevant sandbox analyses, and detection resources such as YARA and SIGMA rules.  

Analysts can also use Threat Intelligence Lookup (TI Lookup) to explore connected activity, uncover related indicators, and proactively search for potential exposure.

Together, these capabilities turn collective threat intelligence into practical insights that strengthen detection and hunting within the SOC. 

Get ANY.RUN TI Reports and accelerate your SOC investigations. 

Conclusion 

Modern phishing attacks are fast, adaptable, and increasingly difficult to distinguish from legitimate activity, putting organizations in the US and all over the world at growing risk of credential theft, fraud, and data loss. 

ANY.RUN’s TI Feeds and TI Reports give SOCs fresh IOCs and expert-curated intelligence to support faster detection, investigation, and threat hunting.

By integrating these capabilities into daily workflows, security teams can respond with greater confidence and reduce the impact of phishing attacks. 



Source link