Spam
Google Calendar is being used as a mechanism for spam

Spammers exploit email meeting invitations

New delivery method can bypass filters

Written by Ian Williams

We can expect to see tools like Google Calendar further abused to contain malicious links and steal sensitive information

Jamz Yaneza Research project manager, Trend Micro

Spammers are using email meeting invitations to circumvent spam filters, security experts have warned.

Trend Micro has tracked spam in numerous formats over the past 12 months, but this is the first time that the Google Calendar system has been used as a mechanism.

Most spam filters are designed automatically to weed out attachment or image spam, but are less likely to be set up to track this new delivery mechanism.

Unlike standard email, meeting invitations contain specialised information in the header allowing them automatically to update and cross-reference the calendaring system.

Extra information such as links and attachments can be added to the invitation, giving the spammers a way to deliver their payload.

Trend Micro said that the email invitations are personalised with a different link sent to each recipient, and may be configured to send meeting alerts in order to draw increased attention to the spam message.

"We will most likely see this delivery method used for other types of spam, such as pump-and-dump, links to web threats, etc," said Jamz Yaneza, research project manager at Trend Micro.

"It is likely that, on the back of this first attack, we can expect to see tools like Google Calendar further abused to contain malicious links and to steal sensitive information."

Trend Micro is warning all businesses and end users to demonstrate extra caution when receiving unexpected meeting invitations and other unexpected mail.

Further reading

McAfee steps up online safety education drive

Firm offers ebook for families and a quiz for teens   More...

Cybercrooks step up taxing attacks

Spammers use bogus downloads to spread malware   More...

Spammers crack Gmail Captcha codes

Sharp rise in spam points to Gmail breach   More...

Lottery scam in sham Oxfam spam

'You've won £850,000!'   More...

Related articles

Precision email attack targets senior execs

Named executives and their relatives singled out in criminal attack   More...

Hackers step up website attacks

Security forecast for 2008 makes grim reading   More...

Tenth of junk email now MP3 spam

Penny stocks promoted as MP3 voice messages   More...

Halloween 'skeleton' spam hides Storm Trojan

Don't let your PC be turned into a zombie   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

09 May 2008

2.51 MBWiMax muddle, Google tactics and asteroid bunkum More...

08 May 2008

3.26 MBBroadband Anywhere, phone-free transport and Web 3.0 More...

07 May 2008

3.19 MBUK success, a paucity of IT women and robot wars More...

Poll

DATA ENCRYPTION

DATA ENCRYPTION

Should encryption be mandatory for all personal data held by companies and governments?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Ofcom

Ofcom outlines future wireless vision

Wi-Fi healthcare and intelligent car brakes in the pipeline   More...

HP

HP Labs opens doors to academia

Innovation Research Program invites proposals related to current research   More...

Advertisement

Asteroid

Nasa plans manned mission to asteroid

Bruce Willis thankfully not going   More...

MySpace

MySpace offers opt-in data sharing

Deals signed with Photobucket, Twitter, eBay and Yahoo   More...

Advertisement