ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Top executives face personal malware threat

Tom Espiner ZDNet.co.uk

Published: 02 Jul 2007 12:36 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Hackers have targeted 500 key business executives in what is believed to be the first mass-targeted malware attack, according to security vendor MessageLabs.

Targeted attacks aim to bypass security measures by individually addressing emails, which often contain zero-day exploits.

On 26 June, MessageLabs intercepted more than 500 individual email attacks targeted at individuals in senior management positions in a variety of organisations around the world. Normally MessageLabs sees approximately 10 targeted attacks per 200 million emails per day, said Mark Sunner, MessageLabs' chief security analyst.

Sentry Posts Blog

Sentry Posts Blog
Guarding the network

What you need to know — and what you and your peers have to tell us — about security management in our new community group blog

Read more +

The malicious emails contain the name and job title of the victim in the subject line. The vertical sector most targeted was banking and finance, with chief investment officers being targeted in 30 percent of the attacks, according to Sunner. However, other verticals were also targeted. Eleven percent of the intended victims were chief executive officers, while six percent were chief finance officers.

Sunner said that the executives being targeted were perhaps "not that tech savvy". In the attacks, an executable file was embedded in a Word document. If the victim opened the document and clicked on a link, the file would have run a data-stealing Trojan that relied on creating buffer overflow conditions in Office documents.

MessageLabs said it did not know who had perpetrated the attack. "It's a certainty that some executives were compromised," said Sunner.

The intended victims' PAs, spouses and relatives were also targeted by name, in attempt to infect other computers related to the victim. The intent was to indirectly gain access to confidential correspondence and intellectual property relating to the target, said MessageLabs.

Sunner said he suspected the hackers harvested the information using search and social-networking sites. "Someone somewhere has really done their homework," said Sunner.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
4 out of 4 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

Senior Level Network Engineer - Finance, Banking, CCNP, Cisco, London

A leading European Financial Derivatives Information Provider based in London has asked us to identify the strongest Cisco Network Engineers in the ...

Credit Risk Analyst - Berkshire - Massive name in household banking

Take the chance to propel your career forward with one of the most recognised names in banking. A great opportunity has arisen for three credit risk ...

Java/J2EE Developer.25,000 - 35,000 London - Banking / Finance

Following the induction period, successful candidates will commence a development programme with the investment-banking client. Your technical skills ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

2 comments