Latest Comments
"it's good one "
by khanbhai | Nov 22, 2008 9:00 PM
 
"when i login to face book it tells me i am cookies enabled what does this mean"
by celeste | Nov 21, 2008 5:15 PM
 
"Hi this is the mail I received Brett Karpman show details Nov 17 (3 days ago) Reply Atten..."
by Rodney Churchyard | Nov 20, 2008 6:13 PM
 
"security through obscurity...shows how detached HIPAA is from reality."
by priceOfFishInChina | Nov 20, 2008 1:19 PM
 
"Umm. no. The 6.5 product is mounting the offline VM image and performing a scan for patch ..."
by eric | Nov 20, 2008 8:15 AM

Olympic spam carries malicious code: MessageLabs

  • Email a Friend
  • Print Page
By Sue Marquette
Feb 26, 2008 10:16 AM
Tags: "olympic | spam" | "spam" | "olympics" | "messagelabs"
The documents, which appear to come from Olympic mail servers, but include embedded malware, are so relevant to the recipient that researchers have noticed many victims are forwarding the malicious messages on to other Olympic committee members.

“These are otherwise perfectly valid documents,” Maksym Shipka, senior architect at MessageLabs, told SCMagazineUS.com today. “It's real information. It's a continuation of actual email conversations. Yet the document is bad.”

Opening the attachment activates a zero-day exploit in Microsoft Word, according to MessageLabs. The document silently extracts and runs the malicious code on the end-user's computer.

Social engineering is one of the most dangerous trends in spam. Messages are tailored to behavioural patterns of the users. Because the attachment is an actual, known document from a trusted sender, the user is tricked into thinking it is safe.

Shipka said the social engineering of this attack has been so precise, the target was compelled to not only open the attachments, but also to pass it on to other Olympic committee members. This marks the first time that such an outcome was intended by the attackers, he said.

Socially engineered attacks make it difficult to tell the difference between what is safe and what is dangerous, meaning that users must now be more vigilant before opening or forwarding any email attachment, Shipka said.

See original article on scmagazineus.com

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
 
Messaging Whitepapers