Spam disguised as PDF attachment
(27/06/2007)
A new form of spam disguised as an Adobe Picture Document Format (PDF) attachment has been reported. The spam takes on the appearance of a legitimate business email containing an attached PDF file.
The PDF features the file name 'username_report.pdf' - the username in the file name is the same as the email recipient's name (taken from their email address). The personalisation of the attachment file name makes it appear more legitimate.
The new spam technique was first used in a recent pump 'n dump spam outbreak that promoted a German company's stock. According to the Marshal TRACE team, we can now expect to see ongoing use of PDF attachments to communicate spam messages.
"Spammers are struggling to find ways to fool spam filters and get their messages into people's inboxes," said Bradley Anstis, Director of Product Management, Marshal. "Using a PDF file as the vehicle for the spam message is an attempt to do just that, as spammers believe that many anti-spam solutions largely ignore PDF files.
"As we recently reported, pump 'n dump spam has declined dramatically and part of the reason for this is overuse of this method. Users are more savvy and can more readily identify a financial scam. With the recent PDF spam outbreak, the spammers have attempted to add credibility and legitimacy to their messages in an attempt to fool users," said Anstis.
"The fact that the message contains a PDF attachment, which is a very common business-related file format, is designed to lower the recipient's suspicions that the message might be spam. We are expecting to see a lot more of PDF spam. The recent pump 'n dump spam case promoting the German company's stocks marks the beginning."
According to Anstis, in the past, spammers avoided this kind of spamming method because attaching file types like PDFs greatly increased the size of the message. Historically spammers used their own servers to send out spam and were inclined to keep the spam size small, enabling them to send out more messages.
Now with the widespread use of zombie networks and spambots, the spammers are less concerned with the size of the message. The spammers have tens of thousands of infected PCs at their command and are able to move large volumes of spam of this type.
Related topics: Virus, Worm, Email security, spyware and malware
Print version |
Email to a friend |
Related articles
Data breaches: Trends, costs and best practices gives you all the latest information on securing personal and corporate data, key recommendations for immediate action to improve data security, and how to respond to data breaches.
Other Security news and resources
Security News
Suppliers Directory
Jobs forum
Classifieds
Knowledge base
White papers
Research library
Security books
Special reports
Security interviews
Security companies
Security events
Security links
Security market
Product channels
Access Control Biometrics CCTV Intruder Alarms IT Security Manned Guarding Perimeter Protection Physical Security Remote Monitoring Security Services Fire, Health & Safety Other Security Products
IT Security white papers and research library
Access Control Authentication Data Management Data Security Digital Signatures Email Security Identity Management Internet Security Intrusion Prevention Network Security Remote access security Security Management Security Policies Security Software Security Threats Virus Detection Software Virus Protection VPN Vulnerability Assessment Wireless Security
Security books, guides, standards and toolkits
RFID and Smart Cards books, guides and reference documents Biometric books, guides and reference documents CCTV books, guides and reference documents Intruder alarms and intrusion detection systems books, guides and reference documents Monitoring and surveillance books, guides and reference documents IT Governance, ISO 27001 ISO 17799 and BS 7799 toolkits Fire, Health & Safety books, guides and reference documents


