Blog

Blog

Phishing-as-a-Service Profile: LabHost Threat Actor Group

Fortra continues to monitor malicious activity targeting Canadian banks by the Phishing-as-a-Service (PhaaS) group known as LabHost. Throughout 2022 and 2023, phishing campaigns linked to PhaaS platforms have surged, as threat actors increasingly rely on subscription-based services to execute attacks. These platforms offer a range of features, including stolen industry branding, real-time...
Blog

Threat Actor Profile: Strox Phishing-as-a-Service

Since early 2022, Fortra has been monitoring a significant ongoing upward trend in fraud activity originating from various Phishing-as-a-Service (PhaaS) operations. Some of these services have thrived, while the popularity of others has diminished. One PhaaS operation that has notably been present throughout is Strox (aka Strox.su or Strox Pages). Strox is one of the most complete phishing...
Blog

Preparing for the Impact of PCI DSS 4.0

Stealing credit card data is a perennial favorite of cybercriminals everywhere, whose aggressive tactics to score sensitive accountholder details result in breach after breach for organizations small and large. In its most recent research on payment card fraud, The Nilson Report found $28.6 billion in losses for 2020 (nearly 36% in the U.S. alone),...
Blog

A Beginners Guide to Protecting Your Data

In this blog, Steph Charbonneau, Senior Director of Industry Strategy at Fortra, talks you through some of the most valuable aspects of data protection and how to measure success of your organizational programs.
Blog

Open PGP for IBM i (iSeries)

GoAnywhere MFT for IBM i (iSeries) includes native commands for performing PGP encryption and decryption functions directly on the IBM i (formerly known as and often still called AS/400). These commands can be placed in CL programs, the job scheduler or run from IBM i menus. With GoAnywhere MFT, files can additionally be digitally signed with a private key on the IBM i. In turn, you can verify...
Blog

IBM i MFT for Secure FTP and PGP

GoAnywhere MFT will automate and secure file transfers on the IBM i platform using Secure FTP, Open PGP and other popular protocols and encryption standards. GoAnywhere's IBM MFT can be installed on IBM iSeries - version 7.1 and higher on IBM Power Systems, as well as many other operating systems. Automates and secures file transfers with trading partners, customers and internal servers ...
Blog

Think Mutual Bank Uses GoAnywhere MFT for Robust Features and PCI DSS Compliance

Industry: Banking and Finance About a year ago, Think Mutual Bank, a bank located in the Midwest, was searching for a way to transfer data between disparate banking systems. Although Think Bank’s core system is the IBM i, the business banking segment runs on MS SQL. Getting all the data into one place (the IBM i), then copying updated files back to the MS SQL system was a challenge that had to be...
Blog

The State of Maryland DLLR Secures and Simplifies File Transfers with GoAnywhere

Maryland’s Department of Labor, Licensing, and Regulation (DLLR) must transfer sensitive data in a secure and reliable fashion. Besides the challenge of ensuring information is protected in transit, each DLLR trading partner requires information to be sent in different file formats, such as fixed width, Excel, CSV, or XML. The DLLR chose GoAnywhere to meet their growing file transfer needs and...
Blog

The Evolution of Cybersecurity Solutions for Organizations

In the early days of the internet, cybersecurity was fairly straightforward, with all solutions and strategies geared toward prevention. While prevention remains critical, cybersecurity has also had to evolve, with businesses layering their defenses and regularly evaluating the status of their safeguards to adapt to change—whether those be organizational or within the wider cybersecurity sphere.
Blog

Abuse of HTTPS on Nearly 75% of all Phishing Sites

Since 2015, PhishLabs (now Fortra Brand Protection) has tracked how threat actors abuse HTTPS or SSL certs. In particular, threat actors often use HTTPS on their phishing sites to add a layer of legitimacy, better mimic the target site in question, and reduce being flagged or blocked from some browsers. In 2014, threat actors hit a significant milestone in this usage when more than 50% of phishing...