Advertisement
Promo

Become a member of the ZDNet UK community

Tech Guide

Targeted Web attacks

Robert Vamosi CNET

Published: 13 Jul 2005

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Forget the notion of a lone script kiddie sitting at a computer, launching wide-scale attacks on random computers around the world. Now that there's good money to be made in criminal hacking, security experts are warning that highly organised groups of attackers are doing their research online before carefully selecting their targets.

The goal is to obtain intellectual property that only an insider would have access to, then offer it for sale or demand a ransom. Armed with an arsenal of custom Trojan horses, these organised criminals are going after secrets within high-profile companies and even within government agencies. Often, the victim is unaware that it's happening.

Warning from the UK
According to a June 16 2005 briefing by the NISCC (National Infrastructure Security Co-ordination Centre, in the United Kingdom), targeted email Trojan horse attacks have increased in sophistication within the last few months. The basic concept is not new (I first wrote about a similar concept two years ago). Similar to phishing attacks or to email-borne viruses, the criminal hackers (a.k.a. 'crackers') target a specific company or government agency, then create a fake email that appears to be an internally sent document. Crackers are literally Googling their quarry, gaining valuable background information regarding the organisational structure of the target system first, then shaping the social engineering part of their email attacks for maximum impact. For example, a subject line might read Re: Project Bluebird, where bluebird is an internal mandate.

Déjà vu
By looking up legitimate email addresses within a particular government agency, then spoofing an email broadcast back to as many recipients of that domain as possible, an attacker can penetrate fairly deeply within an otherwise protected network. According to NISCC, the documents used in these new targeted Trojan horse attacks are often publicly available and usually sent to email distribution lists. The attackers simply modify the original document to include their custom-built Trojan horse.

The irony is that the thieves themselves don't have to know much about programming. Individuals are available on IRC chats and on the Web who will custom-design a Trojan horse to fit specific needs. Because the attacks are so specific, antivirus and security companies may not identify the exact Trojans used to carry out the attack until much later.

Smash and grab
Using known vulnerabilities in Windows, Outlook and Internet Explorer, a targeted Trojan horse can be installed on an insider's computer, often without his or her knowledge. Once in place, these Trojans can record keystrokes, gain access to other parts of the internal network or expose an internal network to a remote attacker. The Trojans can reside on desktops and networks for days or weeks before they are detected. This allows crackers to 'smash and grab' files located deep within a company or government agency before conventional antivirus and security systems recognise there's a problem. I'm speculating that the recent theft of the information on 40 million credit cards from a CardSystems Solutions' database in Arizona might have been accomplished in this stealth manner.

Prevention
Since these attacks rely mostly upon vulnerabilities in software, you should patch your PC regularly. The Windows Update service from Microsoft can be set to run automatically within Windows XP. If you're running older versions, you should check the site manually at least once a month. In addition, good antivirus, personal firewall, and antispyware applications provide layers of security, making it harder for intruders to gain access to your individual PC or private network.

Related articles

ZoneAlarm Pro 5.5

Review ZoneAlarm Pro 5.5 is the best software firewall available to PC users today. [12 Nov 2004]


PC-cillin Internet Security 12

Review PC-cillin Internet Security 12 delivers speedy virus scanning and a host of other Internet protection tools -- all for the price of most antivirus-only programs alone. [01 Nov 2004]


Spybot Search & Destroy 1.3

Review Spybot Search & Destroy accommodates both inexperienced and power users, and it's a great way to keep your PC free of spyware. Best of all, it's free. [17 May 2004]


  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
36 out of 80 people found this useful


Full Talkback thread

0 comments

New Products

System Center Essentials 2010 Beta 1

System Center Essentials 2010 Beta 1

If you spend more time fighting fires than adding business value through IT, it's time to look at Microsoft's comprehensive management solution for medium-sized businesses.

Chrome OS: a first look

Chrome OS: a first look

Google has released source code for a preliminary version of its Linux-based operating system. Is it destined to dominate the netbook market? Here are our first impressions.

Office 2010 Beta: a first look

Office 2010 Beta: a first look

How does the first public beta of Microsoft's next productivity suite differ from the Technical Preview? We have a hands-on evaluation.

Dell Adamo XPS: a first look

Dell Adamo XPS: a first look

More details have finally emerged on Dell's ultra-thin, ultra-stylish Adamo XPS. Check out our preview and image gallery.

View all Previews


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters