PowerPoint now the most common exploit vector
(18/04/2007)
MessageLabs has revealed new data on the levels, victims and sources of targeted email attacks in March 2007. Last month MessageLabs intercepted 716 emails in 249 separate targeted attacks aimed at 216 different organizations. Of these, almost 200 were one-on-one targeted attacks where the tailored attack comprised a single email designed to infiltrate one organization. These numbers represent a significant increase when compared to the same period last year when attack rates reached one or two per day.
For the first time, PowerPoint has emerged as the most common exploit vector, likely driven by the large number of attacks perpetrated by one gang using the same attack file, mostly originating from an IP address within Taiwan. Achieving notoriety as a carrier of typical email viruses, .exe files only accounted for 15 percent of the targeted attacks, while the more familiar Microsoft Office suite accounted for 84 percent of targeted attacks in March 2007.
Other characteristics of these attacks include that they are typically timed to arrive during the busy workday and rarely over a weekend and most commonly target these five industry sectors: electronics, aviation, public sector, retail and communications.
“The bad guys know which organizations have data worth stealing and are picking them out one by one,” said Alex Shipp, Senior Anti-Virus Technologist, MessageLabs. “These targeted attacks are highly difficult to detect as the large majority consist of a single email to one individual, which means they never have anti-virus signatures created by traditional anti-virus software. However, if you happen to be that one company targeted the impact could be devastating. A proactive anti-virus defense, such as MessageLabs Skeptic™ technology is essential along with employee education and vigilance since many of these attacks are highly personalized.”
SkepticTM, MessageLabs proprietary technology, has proven uniquely successful at detecting and stopping previously unknown threats, such as targeted email attacks. In this report, of the 249 attacks stopped, 65 of them were not stopped by any other anti-virus scanner.
Some cyber-criminals continue to use the same attack file relentlessly. One gang has used the same two attack files since November 2006 and in March the gang used these files 151 times, making them one of the highest profile gangs responsible for more than 20 percent of all targeted attack emails.
The attack is launched by execution of an index.exe file from an IP address that belongs to China United Telecommunications Corporation. Once downloaded, the file gives the attacker complete control over the PC. Detection of this exploit was minimal, with only five anti-virus companies, including Skeptic, recognizing the exploit.
Related topics: IT Network and Computer Security Security market sectors
Print version |
Email to a friend |
Related articles
Data breaches: Trends, costs and best practices gives you all the latest information on securing personal and corporate data, key recommendations for immediate action to improve data security, and how to respond to data breaches.
Other Security news and resources
Security News
Suppliers Directory
Jobs forum
Classifieds
Knowledge base
White papers
Research library
Security books
Special reports
Security interviews
Security companies
Security events
Security links
Security market
Product channels
Access Control Biometrics CCTV Intruder Alarms IT Security Manned Guarding Perimeter Protection Physical Security Remote Monitoring Security Services Fire, Health & Safety Other Security Products
IT Security white papers and research library
Access Control Authentication Data Management Data Security Digital Signatures Email Security Identity Management Internet Security Intrusion Prevention Network Security Remote access security Security Management Security Policies Security Software Security Threats Virus Detection Software Virus Protection VPN Vulnerability Assessment Wireless Security
Security books, guides, standards and toolkits
RFID and Smart Cards books, guides and reference documents Biometric books, guides and reference documents CCTV books, guides and reference documents Intruder alarms and intrusion detection systems books, guides and reference documents Monitoring and surveillance books, guides and reference documents IT Governance, ISO 27001 ISO 17799 and BS 7799 toolkits Fire, Health & Safety books, guides and reference documents


