Hackers eye off the boardroom

Criminals have targeted top business executives with malicious e-mails in what MessageLabs believes to be the first mass-targeted software campaign.

The targeted attacks aim to bypass security measures by individually addressing e-mails, which often contain zero-day exploits.

Last week, MessageLabs intercepted more than 500 individual e-mail attacks targeted at individuals in senior management positions in a variety of organisations around the world. Normally, MessageLabs sees approximately 10 targeted attacks per 200 million e-mails per day, according to Mark Sunner, MessageLabs' chief security analyst.

The malicious e-mails contain the name and job title of the victim in the subject line. The vertical sector most targeted was banking and finance, with chief investment officers being targeted in 30 percent of the attacks, according to Sunner. However, other verticals were also targeted. Eleven percent of the intended victims were chief executive officers, while 6 percent were chief finance officers.

Sunner said the executives being targeted were perhaps "not that tech-savvy." In the attacks, an executable file was embedded in a Microsoft Word document. If the victim opened the document and clicked on a link, the file would have run a data-stealing Trojan horse that relied on creating buffer overflow conditions in Office documents.

MessageLabs said it did not know who had perpetrated the attack. "It's a certainty that some executives were compromised," Sunner said.

The intended victims' spouses and relatives were also targeted by name, in attempt to infect other computers related to the victim. The intent was to indirectly gain access to confidential correspondence and intellectual property relating to the target, MessageLabs said.

Sunner said he suspected that the hackers harvested the information using search and social-networking sites. "Someone somewhere has really done their homework,."

Tom Espiner reported for ZDNet UK from London

Like this article? Click below to send it to your mobile for free!

Advertisement

Talkback 0 comments


Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Alex Serpo Is green IT a marketing fad?
    It seems that green IT has dropped off the radar, with other technology issues moving to the fore. But was green IT ever a real technology movement, or was it just a marketing fad?
  • Array Gutless studios have the wrong target
    I have one word for the Australian Federation Against Copyright Theft (AFACT). Gutless.
  • Array NBN needs workers on board
    Without consensus on labour issues, the eventual winner of the NBN may end up as little more than a lame duck and a cashed-up symbol of the conflict between the desire for progress and the lack of mechanisms to deliver it.
  • More blogs »

Tags

Back to top

Featured