Trojan horse
An increasing number of chief executives have been targeted by a new email attack

'Subpoena' spear phishing attacks mount

Senior executives tricked into downloading Trojan

Written by Clement James

Most people will want to discover the details of why and by whom they are being sued

Trygve Aasland Norman

Chief executives have been warned to be on their guard against a campaign of personalised spear phishing attacks.

Reports surfaced last week of emails arriving with bogus subpoenas requesting the named chief executive to click on a link purporting to contain court documents.

The link actually leads to a plug-in that contains a Trojan with the ability to take over the victim's computer.

The reason this attack is so dangerous is that it is correctly addressed and identifies the chief executive by name.

European data security firm Norman said that the emails look very realistic and, unlike many other phishing attempts, use good grammar and spelling.

They contain the correct name of the company, the correct chief executive and can even contain the correct phone number, misleading the recipients into following the instructions.

The link, which appears to lead to the American courts, in fact leads to a server in China, and recipients are asked to install a plug-in to access the 'documents'.

By doing this the victims are in fact installing a Trojan that gives criminals access to data located on the computer.

The Trojan is installed in form of a digitally signed CAB archive which extracts a file called 'acrobat.exe'. This file installs 'acrobat.dll' that gives the Trojan access to all data that passes through the web browser and Windows Explorer.

Current reports show that an increasing number of chief executives have been targeted, and that the apparent legitimacy of the document is proving highly successful for the malware writers.

Trygve Aasland, chief executive at Norman, was one of the recipients. "This email appears legitimate and the technique is clever in that most people will want to discover the details of why and by whom they are being sued," he said.

"Fortunately I am very much aware of these attacks and we remained unaffected. But I can see how others may have been tricked into opening the link and installing the so-called plug in."

Further reading

Email scammers use bogus subpoenas

Phishing attack hides malware in fake court documents   More...

Malware writers cash in on Olympics

Rootkit-laden video is latest to exploit Tibet protests   More...

Tibet attack Trojan identified

'Fribet' also connected to SQL attacks   More...

Malware mimicking legitimate business

R&D budgets, outsourcing models and support services   More...

Related articles

Dutch police nab ABN Amro hackers

14 suspects arrested on money laundering charges   More...

Halloween 'skeleton' spam hides Storm Trojan

Don't let your PC be turned into a zombie   More...

Cyber-gangs gear up for 2008

Let's be careful out there   More...

Malware writers gear up for bumper 2008

Let's be careful out there   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

16 May 2008

2.97 MBXP on OLPC, broken dreams and Yahoo fights back More...

15 May 2008

3.28 MBDark fibre, mobile TV and solar power More...

14 May 2008

2.66 MBOnline inequality, mobile thumbprints and corporate raids More...

Poll

HOME WORKING

HOME WORKING

Do you let any or all of your employees work from home?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

OLPC

OLPC to ship with Windows XP

Microsoft teams up with One Laptop per Child project   More...

The Sims

The Sims goes flat-pack with Ikea

Virtual world gets Swedish wood   More...

Advertisement

Microsoft-Yahoo

Yahoo board fights back at Icahn

Investor accused of 'significant misunderstanding' in Microsoft saga   More...

MySpace

Woman charged over MySpace suicide

Lori Drew indicted on federal charges   More...

Advertisement