Microsoft Shuts Down the Spear Phishing Scheme of Bohrium Hackers

“Hi there. We have detected some suspicious activity on your account. Please click on the link below to reset your password. Thank you and sorry for the inconvenience.”

This is what a run-of-the-mill phishing attack looks like. To succeed, phishing scammers heavily rely on their spoofing ability and, as always, user error.

But this cyberthreat goes even deeper. Spear phishing is commonly targeted at people from rising sectors like IT, education, and e-commerce.

Microsoft’s Digital Crime Unit (DCU) decided to try and put an end to spear phishing. Let’s see how they approached the problem and what all of us can learn from this whole situation.

What is spear phishing?


Spear phishing is a relatively new term, but we already have notorious spear phishing cases, with the list only getting longer. It is a form of phishing that doesn’t only rely on chance and spam but on precision and targeting instead.

The whole point of targeted spear phishing is to extract data from companies and businesses rather than from random people across the internet.

The problem is – this type of cyber attack isn’t for the big players only. And since precision is needed for an attack like this, the hacker group will often do thorough research on the target, which increases their chances of a successful attack.

Who are the targets of spear phishing?


Every business that operates online is a potential target. Again, compared to plain old phishing that is executed at a large scale without much thought, spear phishing attacks require preparation and detailed planning.

So, the most lucrative targets are businesses that have lots of valuable data, specifically those that deal with a large number of customers/clients. The goal of spear phishing is often to extract financial info or user credentials since that is where the value is.

Bohrium hackers and how Microsoft decided to fight them?


An Iranian hacker group named Bohrium recently started a spear phishing operation on high-profile targets. Microsoft’s DCU worked hard at shutting them down. But instead of tracking down the individual cybercriminals, they located the domains connected to the Bohrium group.

A total of 41 domains have been shut down, including some from the pool of “.com”, “.live”, “.org”, and “.net” pool. This made a huge impact on Bohrium operations, which was the goal in the first place – to stop these phishing attacks from happening.

During this whole situation, Microsoft claims that they learned a whole lot about the way these cyber-attacks happen. They say they are working on prevention through security patch updates, all so these attacks stop causing so much damage.

How do you stay safe from spear phishing?


There isn’t a single foolproof solution to protecting your organization from spear phishing attacks. However, there are some security protocols you can implement to help you prevent a cyber crisis and potentially recover if you do get hit by spear phishing.

Here’s a short list of things you can do to avoid getting spear-phished:

  • Raise phishing awareness among your colleagues: you should know that an official support agent will never ask for your credentials.
  • Create solid backups: utilize encryption to lock and protect your data from getting stolen. For extra convenience, you can use encrypted cloud storage for business and have easy and secure access to your data from anywhere and anytime.
  • Create strict sensitive data policies: Restricting sensitive communication through regular channels can save you from a lot of trouble. No one should ask for passwords over DMs.

As you can see, prevention is key when it comes to spear phishing. Because once an attack goes through, there’s not much you can do.

The fight is won, but the war is never over


Hacker groups are quite an unpredictable factor in the cybersecurity world. Microsoft’s DCU did a great job at hindering Bohrium’s main channels of operation. But this doesn’t mean that we should forget about spear phishing.

Stay ahead of the game and level up your cybersecurity protocols asap. Since spear phishing requires thorough target research, it will continue happening less often than regular phishing (for now).

But, in the business world, spear phishing is a threat on the rise. Hackers are getting smarter and more cunning by the day. Stay safe out there!

