Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Email Security

Cybercriminals Increase Targeted Attacks on Retail Businesses in October

Symantec today released its October 2010 MessageLabs Intelligence Report, which showed that cybercriminals are increasingly launched targeted attacks.

According to the report, targeted attacks have increased from one to two attacks per week in 2005 to 77 attacks per day in October 2010.

Symantec today released its October 2010 MessageLabs Intelligence Report, which showed that cybercriminals are increasingly launched targeted attacks.

According to the report, targeted attacks have increased from one to two attacks per week in 2005 to 77 attacks per day in October 2010.

Targeted attacks or Advanced Persistent Threats as they are also known, have the ultimate aim of gaining access to specific sensitive data, corporate intellectual property or access to confidential internal systems. This is undertaken by targeting specific individuals within the companies being targeted. Targeted attack emails are sent in very low volumes, especially when compared with spam and phishing emails, but are potentially one of the most damaging threats any organization can face.

Cybercriminals Using Targeted Attacks

Targeted attacks hit the retail sector hardest in October where they increased from a steady monthly average of .5 percent of all attacks over the past two years to 25 percent in October.

The report notes that between 200 and 300 organizations are typically targeted each month with the industry sector varying. Over time, the same individuals are targeted but using different exploit methods. For example, in October, an average of 5.4 users was targeted within each organization.

“While targeted emails by nature are sent in low volumes, they are one of the most damaging types of malicious attacks,” said MessageLabs Intelligence Senior Analyst Paul Wood. “We have seen a constant influx of targeted attacks over the past six months with the type of organization targeted changing on a monthly basis and the number of targeted users increasing each month. Although the number of unique attack exploits being deployed has diminished slightly, the number of attacks used by each exploit has increased.”

The number of attacks against the retail sector jumped to 516 in the last month, compared to just seven attacks per month for much of 2010 marking the first time the retail sector had been the focus of a targeted attack campaign in recent years.

“Of the 516 attacks, only six organizations were the intended targets but two of them were mainly targeted one of which was the target of 63 percent of the 516 attacks,” Wood said. “The spear phishing attacks, launched in three waves each one week apart, used social engineering techniques to distribute legitimate-looking emails from HR and IT staff of the targeted organization but in actuality contained malicious attachments.”

Advertisement. Scroll to continue reading.

Each wave was comprised of one or two different email messages using different themes. The first wave of emails targeted 50 recipients and spoofed an email address from the firm’s Senior HR Executive with subjects referring to confidential salary information. The attachment contained a malicious PDF. The second wave also spoofed an HR Executive and targeted 20 recipients with a subject line pertaining to new employment opportunities.

The malicious attachment was an XLS file. The third wave took a slightly different approach and spoofed one of the organization’s Senior IT Security Executives. It targeted 70 employees and requested action with a critical security update. The malicious attachment was a password-protected zip file.

“Examination of the attacks’ timing and techniques suggests a methodical approach on behalf of the attackers,” Wood said. “In the case that the recipient clicked on any of the three malicious attachments, a backdoor Trojan would have been installed onto the computer with the potential for the attacker to gain access to any sensitive personal information or valuable corporate data on the machine.”

The report notes that in October, phishing activity was 1 in 488.0 emails (0.20 percent), a decrease of 0.06 percentage points since September. According to the most recent APWG Global Phishing Survey, activity from the Avalanche phishing gang, the world’s most prolific phishing group, dropped significantly as a result of changing strategies to malware distribution.

The full October 2010 MessageLabs Intelligence Report is available at: http://www.messagelabs.com/intelligence.aspx

Subscribe to SecurityWeek

Written By

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Kim Larsen is new Chief Information Security Officer at Keepit

Professional services company Slalom has appointed Christopher Burger as its first CISO.

Allied Universal announced that Deanna Steele has joined the company as CIO for North America.

More People On The Move

Expert Insights

Related Content

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Cybercrime

The changing nature of what we still generally call ransomware will continue through 2023, driven by three primary conditions.

Cloud Security

Cloud security researcher warns that stolen Microsoft signing key was more powerful and not limited to Outlook.com and Exchange Online.

Malware & Threats

The NSA and FBI warn that a Chinese state-sponsored APT called BlackTech is hacking into network edge devices and using firmware implants to silently...

Compliance

Government agencies in the United States have made progress in the implementation of the DMARC standard in response to a Department of Homeland Security...

Email Security

Many Fortune 500, FTSE 100 and ASX 100 companies have failed to properly implement the DMARC standard, exposing their customers and partners to phishing...

Cyberwarfare

An engineer recruited by intelligence services reportedly used a water pump to deliver Stuxnet, which reportedly cost $1-2 billion to develop.

Application Security

Virtualization technology giant VMware on Tuesday shipped urgent updates to fix a trio of security problems in multiple software products, including a virtual machine...