A new threat is emerging that even your name-brand email security solutions may have trouble catching. Traditionally, email security features and Identity Threat Detection & Response (ITDR) will identify anomalous login activity and shut down the access before the attacker can cash in. Multiple successful logins from different locations and logins from strange VPN services that the user has never used are easy to catch, but what if these malicious logins actually come from your general location without using a VPN? What if the login looks like it’s coming from just down the street at a friend’s house? This is why a Residential Proxy Attack is so dangerous because you have to rely on other, often more ambiguous, factors to conclude that a user is compromised.
In March of this year, the FBI put out a Public Service Announcement describing what a Residential Proxy Attack is and how to protect against it. In the article, the FBI describes how a Residential Proxy attack works: “A residential proxy is used to route users’ requests through another IoT device, typically located elsewhere in the world. When selecting an IP address, users can choose which country they would like the IP address from, down to the city and state. Doing so alters the users’ IP address from the perspective of the website to that of the device the traffic was routed through.”
There are several ways a Residential Attack can utilize a geographically close location, but the most surprising way this can work is actually with the consent of app developers. Mobile app developers can allow 3rd party organizations to “rent” their end user bandwidth to route traffic through the device for a fee. The app developers do this because it’s an extra stream of income, but attackers can leverage this service to launch attacks and fool traditional email security. Oftentimes, the traffic will show up as coming from a residential ISP which makes it nearly impossible to detect just on IP login alone.
Petra Security, one of the newer email security providers in the industry, recently claimed that just north of 50% of all business email compromises now leverage this technique, up from 5% just a year ago. Business Email Compromises remain a staple in the cyber threat landscape and organizations must manage this risk.
So how do you protect against this new threat? The short answer is that email security can no longer rely solely on location-based ITDR, they also need to utilize Behavioral ITDR. For example, does the user in question normally interact with a particular SharePoint site? Is it odd for this user to upload tons of data from their OneDrive at 1am? Your security solution needs to analyze the intent of the user and not just the action.
This is where CDS steps in and protects against this threat, among others. Our ITDR solution looks for both the user behavior and the more traditional location-based anomalies. Businesses cannot grow complacent in the cyber security space when new and emerging threats are the norm, not the exception.


