Trojan horse
An increasing number of chief executives have been targeted by a new email attack
R E L A T E D   C O N T E N T
ADVERTISEMENT

'Subpoena' spear phishing attacks mount

Senior executives tricked into downloading Trojan

Clement James, vnunet.com 21 Apr 2008
ADVERTISEMENT

Chief executives have been warned to be on their guard against a campaign of personalised spear phishing attacks.

Reports surfaced last week of emails arriving with bogus subpoenas requesting the named chief executive to click on a link purporting to contain court documents.

The link actually leads to a plug-in that contains a Trojan with the ability to take over the victim's computer.

The reason this attack is so dangerous is that it is correctly addressed and identifies the chief executive by name.

European data security firm Norman said that the emails look very realistic and, unlike many other phishing attempts, use good grammar and spelling.

They contain the correct name of the company, the correct chief executive and can even contain the correct phone number, misleading the recipients into following the instructions.

The link, which appears to lead to the American courts, in fact leads to a server in China, and recipients are asked to install a plug-in to access the 'documents'.

By doing this the victims are in fact installing a Trojan that gives criminals access to data located on the computer.

The Trojan is installed in form of a digitally signed CAB archive which extracts a file called 'acrobat.exe'. This file installs 'acrobat.dll' that gives the Trojan access to all data that passes through the web browser and Windows Explorer.

Current reports show that an increasing number of chief executives have been targeted, and that the apparent legitimacy of the document is proving highly successful for the malware writers.

Trygve Aasland, chief executive at Norman, was one of the recipients. "This email appears legitimate and the technique is clever in that most people will want to discover the details of why and by whom they are being sued," he said.

"Fortunately I am very much aware of these attacks and we remained unaffected. But I can see how others may have been tricked into opening the link and installing the so-called plug in."

Beijing OlympicsRootkit-laden video is latest to exploit Tibet protests  15 Apr 2008
'Fribet' also connected to SQL attacks  11 Apr 2008
Data protectionR&D budgets, outsourcing models and support services  08 Apr 2008

All Enterprise Security Technology
Tags: Phishing, Security

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Inverness, United Kingdom | NHS Scotland
CORPORATE SERVICES E-HEALTH DEPARTMENT  RAIGMORE HOSPITAL INVERNESS TECHNICAL DEVELOPMENT TEAM IT TECHNICAL SPECIALIST  £24,103 to £32,653 PA An exciting opportunity has arisen to join the technical development team within the eHealth Department. We are looking ... more >
London, United Kingdom | City of London
ICT Support Officer £27,320 - £33,370 pa inc. depending on experience (pay award pending) Maternity cover for up to one year Guildhall, London EC2 Bring your IT experience to one of the country's most prestigious ... more >
London, United Kingdom | Royal Borough of Kensington and Chelsea
Web Content Manager - c.£40,000 plus bonus - London   As one of the country's best-performing councils, we're always looking for new ways to improve on excellence. Providing an innovative, high-quality internet site for our ... more >
Telford, Shropshire, United Kingdom | EDS
EDS are currently looking to recruit a PMO Support Analyst to join our Project Management Defence team in Telford, Shropshire. Summary: Within DII Service Management. To perform the PMO function for SM Service Introduction. This ... more >
More job opportunities