C-level employees targeted in trojan attack

C-level employees of publicly listed companies are being targeted by cybercriminals using malware-infected RTF (Rich Text File) documents disguised as recruitment letters.

Security vendor MesssageLabs reported that 1,100 e-mails containing malware-infected RTF attachments have been recorded over a 16-hour period this month. Four separate waves appeared between 13 and 14 September, the company said.

"All [the emails] were going after C-level management. The e-mails included the company name in subject field, purporting to be a recruitment company. What it had in the attachment is an executable RTF file," a MessageLabs spokesperson said.

Similar e-mails were noticed in June this year, he said.

The e-mail, which contained no body text, included an .SCR screen saver dummy file within an executable RTF file, the spokesperson said. When recipients attempt to open the file, a message is displayed stating: "Microsoft has encountered an error and had to close." The recipient is then advised: "To view this, double click on the message."

Once activated, the RTF file starts a chain of downloads which establish a secure connection between the attacker's server and the infected computer.

The C-level nature of the targets clearly indicates that the attackers are after information, MessageLabs spokesperson said, but the greater concern is the social engineering technique used to spread the trojan-harbouring e-mail.

"The way that this works has the potential to be so effective. You are getting that top down approach -- if they forward that e-mail on internally, that e-mail is coming from a trusted source," he said.

The spokesperson added that all the e-mails were addressed to a single person, which helps diminish their conspicuousness.

F-Secure security expert Patrik Runald recently postulated that the perfect attack would be a zero-day attack using a rootkit-cloaked trojan sent to an HR manager who, due to company policy, would be compelled to open the document.

He told ZDNet Australia: "These are scary cases because it's really hard to protect yourself against. We have to run Office and we have to allow Word, RTF, PowerPoint and Excel files through. It shows that signature based antivirus is not enough; you need more technology than that."

Runald said there is little organisations can do to protect against these threat types besides educating users of the risks because banning the receipt of common file types is impractical.

Heuristic or behavioural-based monitoring is proving to be more effective at blocking these attacks since the behaviour of the file remains the same despite different signatures being used, he said.

Advertisement

Talkback 0 comments

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal Sick of broken tender sites
    Some of the state governments desperately need to invest in more user-friendly tender sites so that looking for information on government tenders doesn't have to be a game of blind man's bluff.
  • Array Cyberwar: What is it good for?
    In this week's episode, Cyberwar. What is Australia's place in the world of digital warfare? What are the implications for the NBN?
  • Array Is wholesale-only backhaul just a pipedream?
    The potential acquisition of Pipe Networks by SP Telemedia has raised the question about whether vertically integrated backhaul providers will mean higher wholesale prices for ISP customers.
  • More blogs »

Tags

Back to top

Featured