Sunday | 7 September, 2008
Computerworld
Hackers target C-level execs and their families
Hackers are increasingly targeting C-level executives with one-off e-mails containing malicious attachments designed to steal data, MessageLabs said.
Jeremy Kirk (IDG News Service) 03/07/2007 10:48:23

Computerworld Buyer's Guide - Vendors Matched to this Article
Related Features
  • +

    Ticked Off at Tick the Box Mentality 04/02/2008 13:01:15

    Does your executive search firm know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?
    Does your executive search firm know its MIS managers from its elbow? Does it even know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?
  • +

    Your World. . . Hacked 02/10/2007 10:51:23

    As your business becomes more collaborative and global, the risks to your company’s trade secrets rise proportionally. Fortunately, there are new strategies to protect the data that allows you to compete
    The call to Bob Bailey, an IT executive with a major US government contractor, came on an otherwise ordinary day in October 2003. "Why are you attacking us?" demanded the caller, an IT leader with a Silicon Valley manufacturer. He wanted to know why Bailey's company had launched a denial-of-service attack against his network
Additional Resources
Executive Guides
Whitepapers
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.

Newsletter Subscription

Sign up for our Computerworld newsletters!
Computerworld's twice-daily news service keeps you in touch with the latest, most important headlines from Australia and around the world.
Keep up with the latest virtualisation technologies, products, news and features.
RSS Feeds

Hackers appear to have stepped up their efforts to trick corporate executives into downloading malicious software programs that can steal company data over the past year, according to new data released Monday.

MessageLabs, a security vendor that offers e-mail filtering services to catch spam and malicious attachments, caught an average of 10 e-mails per day in May targeted at people in senior management positions, up from just one a day a year prior, said Mark Sunner, chief security analyst.

Those 10 e-mails are a very small percentage of the 200 million e-mails that MessageLabs scans every day, but the composition of those messages is what's alarming, Sunner said.

Many of the e-mails contained the name and title of the executive in the subject line, as well as a malicious Microsoft Word document containing executable code. The hackers are trying to trick the victim into thinking the messages comes from someone they know, in the hope that the victim will willingly install, for example, a program that can record keystrokes.

MessageLabs won't reveal what companies have been targeted of late, but it has contacted executives who have been targeted and heard their family members have also received messages on their own, non-corporate e-mail accounts, Sunner said.

Those methods suggests that hackers may be researching victims and culling data from social networking sites such as Linked In, MySpace or Facebook, Sunner said.

"If you really want to work out somebody's background ... you can actually find out a lot," Sunner said.

Tricking a relative into installing malicious code would offer the hacker another way to collect sensitive data, if an executive decides to do some work on a home computer, Sunner said.

During June, MessageLabs picked up more than 500 of these targeted messages, with some 30 percent aimed at chief investment officers -- a position that can include handling acquisitions and mergers. Other positions targeted include directors of research and development, company presidents, CEOs, CIOs and CFOs.

Another danger is that the targeted messages are often just single messages sent to a single person, rather than a mass spam run. When hackers send out millions of messages, security companies often either update their software or change their spam filters to trap the bad messages.

But single messages have a higher chance of slipping through, although Sunner said MessageLabs' filtering service catches the messages by analyzing the e-mail's attachment and determining whether it is potentially harmful. Other security companies catch malware by updating their software with indicators, or signatures, to detect harmful code or block code from running based on what it does on a computer, a technology called behavioral detection.

Tracing where the messages come from is difficult, since the sender's name is always fake, Sunner said. The IP address from which the messages were sent indicate computers that are located around the world. Hackers often use networks of computers they already control, called botnets, to send e-mails.

"Certainly, people need to raise the level of vigilance," Sunner said.

Computerworld Buyer's Guide - Vendors Matched to this Article
Market Place

Computerworld Member Login


 

Prioritizing Services with IT Service Management (ITSM)

Computerworld Live Webinar
Wednesday 20th, August 2008
11:00am EST (Sydney, Australia)

To be repeated on:

Thursday 4th, September 2008
11:00am EST (Sydney Australia)

Sign up and receive a free copy of The Forrester WaveTM Service Desk Management Tools, Q2 2008 at the conclusion of the Webinar.

Attend and discover:

  • How to deliver value to your business through ITSM
  • Best practice ITSM implementation
  • Why emphasis is changing from optimizing IT management processes to better servicing customers and demonstrating real dollar value
  • If service-oriented ITSM is best for your business
Whitepaper

Network Aware Service Management

Today's complex, distributed and virtualised IT environments are almost impossible to manage. Learn how to obtain end-to-end visibility, as well as automated root cause analysis from within Microsoft's System Centre Operations Manager 2007, creating a unique solution that addresses the need for network-aware, end-to-end service management.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links