ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Mail & messaging Toolkit

Yellow Fever

Facebook enabling tailored email attacks

Ina Fried CNET News.com

Published: 21 Nov 2007 12:24 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security experts warned this week of two separate email attacks launched on Monday that take aim at specific individuals within corporations.

The first attack, detected by MessageLabs at 4.55pm on Monday, was sent to more than 400 individuals at financial institutions, with the email addressed specifically to that individual and purporting to be a complaint from the US Department of Justice. A second attack, spotted three and a half hours later, was similar, but claimed to be from the Better Business Bureau. In both cases, the emails contained malicious attachments that could lead to the recipient's system being taken over.

The Trojan horse that gets installed on a computer allows an attacker to gain remote access to the machine, but MessageLabs security analyst Paul Wood said the attacker's exact purpose was not clear. "Once they get access to the machine remotely, they can use that machine for anything," Wood said.

Although it is likely the two attacks are related, Wood said, their attachments and delivery mechanisms varied somewhat. The attack spoofing the Justice Department contained an executable program within a zipped file with the extension .scr, typically used by screen savers. In the attack claiming to be from the Better Business Bureau, the attachment was a rich text format document that contained an executable program disguised as a PDF file.

The rise in specifically targeted email attacks has been of significant concern to security experts. Such attacks are both harder to detect than mass phishing attacks, and more likely to be acted on, given the fact they are customised to their recipients, including details such as their name and official title.

In its annual Security Intelligence Report, issued last month, Microsoft reported a steep rise in such attacks. Wood said that his company started seeing attacks aimed at specific individuals back in 2005, but, at the time, it saw maybe two such attacks a week. By last year, it was seeing one per day; this year, that number has risen to an average of 10 per day.

One of the big reasons behind the increase is the availability of toolkits that enable criminals to essentially have a template for the attacks, in which they need to fill in only the targeted information.

"A year or two ago you would have to be fairly technically sophisticated in order to create these attacks," Wood said.

Wood added that the rise of social networks, like Facebook, and professional networks, such as Plaxo and LinkedIn, is making it easier for attackers to do their homework on potential victims.

"You can certainly build up a profile and make those attacks much more convincing," Wood said.

This week's attacks are similar to ones that took place in June and September. In the September attack, more than 1,000 senior executives were sent messages with an apparent Word attachment that contained an embedded executable file. The June attack, which also targeted senior executives, purported to be an invoice.

The latest attack claiming to be from the Better Business Bureau is still ongoing, said MessageLabs. The Better Business Bureau has also been imitated before in a number of phishing attacks.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
2 out of 2 people found this useful


Full Talkback thread

0 comments


More in this Special Report

Social networking: 3G's killer app?

Social networking: 3G's killer app?

Social networking Web sites such as MySpace.com, which will soon go mobile, could become key applications driving data usage on new 3G wireless networks more

Half of employers ban Facebook

Half of employers ban Facebook

Half of businesses are restricting employees' access to social-networking site Facebook, due to concerns about productivity and security, according to security vendor Sophos more

Social networking driving server sales

Social networking driving server sales

Social networking is pushing up server sales despite the increasing adoption of virtualisation technology, according to Sun more

Think before you mail, advises IBM

Think before you mail, advises IBM

IBM's Darren Adams says it's time to think outside the inbox when it comes to businesss collaboration more

Facing the past and future at Facebook

Facing the past and future at Facebook

Joe Hewitt developed a version of Facebook for Apple's iPhone more

Unified communications come together

Unified communications come together

Lotus's Darren Adams talks about the benefits of integrating VoIP, video, presence, telephony, unified messaging and other technologies more

Microsoft bags a stake in Facebook

Microsoft bags a stake in Facebook

The software giant has beaten Google to a chunk of the popular social-networking site, agreeing to pay $240m for a 1.6 percent stake more

Google: Businesses can benefit from video sharing

Google: Businesses can benefit from video sharing

Web 2.0 technology such as video and social networking has the potential to be incredibly valuable in the business world, according to the search giant more

Facebook: A boon to business security?

Facebook: A boon to business security?

The Australian division of GE Commercial Finance is using Facebook to educate staff in good security practices more

Vendorboard: Freeing yourself from inbox tyranny

Vendorboard: Freeing yourself from inbox tyranny

Darren Adams, messaging and collaboration sales leader at IBM, argues instant messaging can help cut email traffic by up to 40 percent more

How to use social networks for business gain

How to use social networks for business gain

Applications such as Facebook are seen as a distraction by some employers but, if managed in the right way, the technology can actually improve business collaboration more

Google reveals its social side

Google reveals its social side

The company has finally unveiled its social-networking strategy, OpenSocial, and it's ambitious even for the seemingly unshakeable search giant more

Company/Topic Alerts

Create a new alert from the list below:









Related Jobs

MDX and CUBE experts,Get into the exciting world of Investment Banking

Seeking an intelligent and experienced Business Intelligence consultant to work on exciting projects, developing reports to advise and improve the ...

IBM Maximo Solution Architect

Maximo Practice, and in collaboration with sales, customer support, and product development, as well as with client IT owners, business process ...

Implementation Consultant - Calypso or Murex experts required !!

Leading Investment banking consultancy is currently looking for a specialist implementation consultant to join their growing specialist department. ...

Featured White Papers

See All White Papers

On the Road Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Eee 1000 + iPhone 3G = the ultimate mo...

Having left the comforting bosom of ZDNet.co.uk to strike out on my own as a freelance journalist recently, I found myself contemplating a shocking truth – I was going to have to shell... More

Post a comment

IE8 puts dim wits ahead of tech savvy

You may have heard that IE8 will suppress subdomains on sites. This means if you have a website with a subdomain for different channels/sections - e.g. videos.cnet.co.uk it will display... More

Post a comment