Phishing
Users have been sent personalised emails claiming to be from a US federal court

Email scammers use bogus subpoenas

Phishing attack hides malware in fake court documents

Written by Shaun Nichols in California

This scam properly identified each chief executive and sent it to his email address directly

John Bambenek Sans Institute

A new targeted phishing attack is attempting to dupe users into downloading malware by sending bogus court subpoenas.

Users are sent personalised emails claiming to be from a US federal court. The target is then asked to download what is supposedly a series of documents on the case.

Instead, the user downloads a malware package which records security certificates from the browser and uploads them to a server in Singapore.

The US government has issued a warning about the attack, pointing out that all court subpoenas are delivered by hand, and that users should therefore consider any subpoena delivered by email to be suspicious.

"The emails in question appear to be sent from a similar address that is not owned and operated by the federal courts," government officials said. "Law enforcement authorities have been notified."

The attacks use a method known as 'spear phishing' designed to steal information from specific high-value targets.

The attacker targets chief executives, for example, delivering personalised emails which evade spam filters and can appear authentic.

"An interesting component of this scam is that it properly identified each chief executive and sent it to his email address directly," wrote Sans researcher John Bambenek. "It is very highly targeted."

Further reading

Just one in nine UK surfers feels safe online

Spam still one of the biggest problems   More...

Phishers target MasterCard users

Cyber crooks getting more subtle   More...

Malware mimicking legitimate business

R&D budgets, outsourcing models and support services   More...

Spyware authors offer dollars for downloads

Botnet operators offered cash to spread malware   More...

Related articles

'Subpoena' spear phishing attacks mount

Senior executives tricked into downloading Trojan   More...

The main internet threats for 2008

Mobile malware, botnets, phishing and ID theft   More...

Spear phishers target US students

Attacks disguised as 'database update'   More...

Greeting card attacks resurface

'Hallmark' cards deliver nasty message   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

25 Jul 2008

7.85 MBPodcast Special: Views from the Valley More...

24 Jul 2008

3.68 MBSpammer jailed, Esquire e-cover, and network passwords More...

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Credit card transaction

Credit card fraud rampant in the UK

Attempted frauds go unreported and ignored, analysts claim   More...

Intel

Intel rolls out new embedded line-up

System-on-a-chip offerings promise footprint and power saving   More...

Advertisement

Network cables

Tech giants collaborate on wireless HD

Another attempt at cable-free transmission in the home   More...

iPhone fever fills AT&T coffers

US provider cashes in on Apple smartphone   More...

Advertisement