How IT teams can prevent phishing attacks with Malwarebytes DNS filtering
Phishing attacks are a persistent threat to businesses globally.Â
According to Verizon, 82 percent of data breaches in 2021 involved the human elementâwith phishing attacks making up over 60 precent of these. And if it ainât broke, donât fix it: threat actors have only continued to use phishing to attack businesses in 2022, with the Anti-Phishing Working Group (APWG) recording a 15 percent increase in phishing attacks in Q1 2022 compared to Q4 2021.
With Malwarebytes DNS filtering, however, you can prevent a large swath of phishing attacks. Our DNS filtering module extends our Nebula platform to help prevent risks introduced from nefarious websites and downloadable web content.
In this post, weâll walk through what it looks like to block phishing attacks with Malwarebytes DNS filtering.
How to block phishing domains with DNS filteringÂ
Letâs say one of your employees gets an email like the one below.Â
Without some kind of phishing protection in place, after clicking on a link in the email thereâs a chance the employee might give up some sensitive information or be tricked into downloading a malicious program.
Obviously, we want to prevent that.Â
Letâs press pause here and go back in time to set up our DNS filter in Nebula.Â
Above, youâll see the dashboard for the DNS Filtering module in Nebula.
Letâs navigate to the âRulesâ section and hit âNewâ.
Here, weâre prompted to name the rule and also select a policy to which the rule should be applied.Â
Iâm naming mine âPhishing blockâ and applying it to four of my endpoints.
Heading over to the âCategoriesâ page, we see that âUse preconfigured settingsâ is enabled by default. This automatically blocks each subcategory in the âSecurityâ category.
For demonstration purposes, weâll leave this untoggled. Just know that each of these security subcategories are available (and recommended to use)!
Letâs scroll down to the âPhishingâ option and toggle it.
I
Under allow lists you can add domains to exclude from this DNS rule. Weâll leave it blank: we donât want to allow any phishing sites!
You can also add domains to block certain domains. Weâll also leave this blank!
Letâs flash forward in time to our employee who received the phishing email. Unfortunately, they clicked a URL in itâbut no need to worry.Â
Our DNS filtering kicked in and blocked the site, the outcome of which you can see below.
This is the default page, but can even customize it to your liking by going to the âGlobal Settingsâ tab.Â
How does it work?
It works because Malwarebytes DNS filtering is powered by Cloudflare, which has a massive database of known phishing sites to which we can instantly block access using the intuitive Nebula UI.
But what happens if a phishing website somehow gets through and a malicious program (ransomware, for example) is installed on an endpoint?Â
The answer is part of what makes our DNS filtering solution so holistic: because it is an add-on to our Endpoint Detection and Response product, a threat that gets through can be detected and mitigated using our EDRâs isolation and remediation capabilities.Â
In other words, DNS filtering helps you filter the easily-blocked known threats, giving time back to your organization to focus on remediating the threats that do get through with our EDR.
Block threats from infiltrating browsers and web-based apps
Malwarebytes DNS Filtering module for Nebula helps block access to malicious websites and limit threats introduced by suspicious content.Â
While we focused on preventing phishing threats in this post, the story doesnât end there. You can also block access to spyware, DNS tunneling, crypto mining sites, and many other websites and domains that pose a security risk.Â
Malwarebytes DNS Filtering is a part of our EDR, which prevents, detects, and responds to ransomware, malware, trojans, rootkits, backdoors, viruses, brute force attacks, and “zero-day” unknown threats so you can avoid business disruption and financial loss.Â
Complete cyberthreat protection starts here
Read the Malwarebytes DNS filtering datasheet.Â
Further reading
3 ways DNS filtering can save SMBs from cyberattacks
DNS security for your small business
Introducing Malwarebytes DNS Filtering module: How to block sites and create policy rules