Phishing attack: Your keyloggers are in the mail

A low-tech approach to phishing has caught a NSW-based organisation after its employees were mailed CD-ROMs containing hidden keylogging software.

While the identity of the organisation has not been revealed, the perpetrators knew their target as the CD-ROMs were addressed to the organisation.

AusCERT (Australian Computer Emergency Response Team) spokesperson Macleonard Starkey told ITRadio.com.au that, once inserted into staff computers, the CDs started a Windows Media Player executable file. In the background, keylogging software was downloaded.

"Because most users have administrative access to their machines, even in corporate networks today, it will usually be dropped straight to the Windows system32 directory, and start up from there. This is a very low-tech scam but it's also a very good one," Starkey said.

He declined to reveal the name of the affected organisation or its industry.

"It's quite likely that this could be carried out by someone who attended a conference and sent some information that relates to someone else," Starkey told ZDNet Australia in a phone interview this morning.

The organisation became aware of the problem after its antivirus software detected the data being sent. It then informed AusCERT which is still examining the malware.

Starkey could not say whether much data was compromised. The scam was a good one as few organisations had control measures in place to guard against this type of attack, he added.

"I don't know of any organisations other than that of Defence that have policies to deal with attacks like this."

AusCERT has seen this type of attack before, but for every one that occurs, "there's probably 20 we don't hear about", he said.

Starkey did not say whether police were investigating the incident.

Advertisement

Talkback 0 comments


Latest Videos

Blogs

  • David Braue Will Rudd's bush backhaul bonanza deliver?
    Rural areas will be welcoming the government's decision to put its money where its politicising is, funnelling $250m into a regional fibre upgrade to six rural centres. Remedying over a decade of near-neglect at the hands of telecoms privatisation, the investment could be the firmest step yet for Labor's NBN dream — but with inevitable political questions and a looming election, Rudd and Conroy need to deliver, and quickly, to preserve the NBN's credibility.
  • Array Doing for AV what VoIP did for telephony
    Sydney-based start-up Audinate is making traditional analog cabling obsolete in favour of TCP/IP-based networking technology. And it's doing a pretty good job so far, with its technology used by World Youth Day and the Sydney Opera House.
  • Array WiMax in Australia: Part two
    WiMax could be the standard that drives the next phase of mobile broadband, it provides an opportunity for players wanting to establish a pure IP network to carry voice and data effectively — but is this what operators want?
  • More blogs »

Tags

Back to top

Featured