Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 24 guests and 2 members online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Resourcesarrow News from the Outside Worldarrow Targetted attacks at CEOs
Ethical Hacker Community Forums
December 01, 2008, 11:46:55 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100! www.chicagocon.com/content/view/103/51/
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Targetted attacks at CEOs  (Read 1614 times)
0 Members and 1 Guest are viewing this topic.
RoleReversal
Sr. Member
****
Offline Offline

Posts: 469


View Profile WWW
« on: April 15, 2008, 04:19:40 AM »

Guys,

ISC has a story about a new 'click-the-link' email scam with a twist. It appears to be targetted at company CEOs claiming they have been issued a subpoena to give evidence in court. (Story here)

These sort of attacks appear to be gaining in popularity. From my experience this could be a scary trend as CEOs (and other director type roles) are often the least technically savvy in an organisation, along with often the worst security and patch level. I can't help thinking these are targets are going to be successful, and likely becoming less of a rarity.

<Update>
Forgot to mention, as is often the case AV covereage is poor 3/32 on VirusTotal
</update>

Who fancies interrupting a round of golf to ask the top man not to click the pretty links?  (me neither...)
« Last Edit: April 15, 2008, 04:21:32 AM by RoleReversal » Logged

A little bit of sanity:
http://www.infosanity.co.uk
pseud0
Full Member
***
Offline Offline

Posts: 142



View Profile
« Reply #1 on: April 15, 2008, 09:05:57 AM »

We added this style of attack to our risk briefings for CISOs about 6 months ago.  This is a version of the spear phishing attempts that have been gaining momentum, but the subpoena line is a new one to me.  Good post.
Logged

CISSP, CISM
sgt_mjc
Full Member
***
Offline Offline

Posts: 158


View Profile
« Reply #2 on: April 15, 2008, 09:54:12 AM »

Thanks for the heads up.
Logged

Mike Conway
CompTia Security +
C|EH
Kev
Sr. Member
****
Offline Offline

Posts: 348


View Profile
« Reply #3 on: April 15, 2008, 07:13:21 PM »

Several years ago there was marketing research done by a direct mail company to determine which mail people were most likely to open first. The number one winner was a notice from the IRS that might look like an audit and the second place winner was mail from an attorney office that might look like a lawsuit. I can testify to the accuracy of this research when I have done social engineering. One time I actually sent an email so obviously a hoax just to prove a point from a law firm I called Dewey, Cheatum and Howe and it stilled worked, LOL! The officer of the company was rather embarrassed later on when I brought it to his attention.
Logged
sgt_mjc
Full Member
***
Offline Offline

Posts: 158


View Profile
« Reply #4 on: April 17, 2008, 09:33:27 AM »

Kev,

You truly are the lowest form of life on Earth. lol  I'll bet he felt like a hoarses @$$ afterwards. Great use of social engineering and it goes to prove where the weakest link in any security is, the end user.
Logged

Mike Conway
CompTia Security +
C|EH
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.046 seconds with 22 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
During the most recent election, I:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.