<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Barracuda Labs Internet Security Blog &#187; spear-phishing</title>
	<atom:link href="http://www.barracudalabs.com/wordpress/index.php/tag/spear-phishing/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.barracudalabs.com/wordpress</link>
	<description></description>
	<lastBuildDate>Thu, 02 Feb 2012 14:24:57 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1</generator>
		<item>
		<title>Human Rights Group Used to Spy on Activists</title>
		<link>http://www.barracudalabs.com/wordpress/index.php/2011/12/22/authoritarian-regime-uses-human-rights-group-to-spy-on-activists/</link>
		<comments>http://www.barracudalabs.com/wordpress/index.php/2011/12/22/authoritarian-regime-uses-human-rights-group-to-spy-on-activists/#comments</comments>
		<pubDate>Thu, 22 Dec 2011 17:44:25 +0000</pubDate>
		<dc:creator>Paul Royal</dc:creator>
				<category><![CDATA[Current Events]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[spear-phishing]]></category>

		<guid isPermaLink="false">http://www.barracudalabs.com/wordpress/?p=2216</guid>
		<description><![CDATA[By Paul Royal, Research Consultant Amnesty International&#8217;s UK website has been compromised and is serving drive-by downloads. Historical data indicates the website AIUK was compromised on or before Friday, December 16. Details: Visiting hxxp://www[.]amnesty[.]org[.]uk loads hxxp://3max[.]com[.]br/cgi-bin/ai/ai.html via an iframe. 3max.com.br, which itself is a legitimate but compromised Brazilian automotive website, loads malicious Java content (stolen [...]]]></description>
			<content:encoded><![CDATA[<p><em>By Paul Royal, Research Consultant<br />
</em></p>
<p>Amnesty International&#8217;s UK website has been compromised and is serving drive-by downloads. Historical data indicates the website AIUK was compromised on or before Friday, December 16.</p>
<p>Details:</p>
<p>Visiting hxxp://www[.]amnesty[.]org[.]uk loads hxxp://3max[.]com[.]br/cgi-bin/ai/ai.html via an iframe. 3max.com.br, which itself is a legitimate but compromised Brazilian automotive website, loads malicious Java content (stolen from the <a href="https://metasploit.com/svn/framework3/trunk/external/source/exploits/CVE-2011-3544/Exploit.java">Metasploit project</a>), which targets CVE-2011-3544. If the exploit is successful, malware is installed on the visitor&#8217;s system.</p>
<p>Details of Vulnerability Targeted by the Exploit<br />
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3544">http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3544</a><br />
VirusTotal Detections for Exploit<br />
<a href="http://www.virustotal.com/file-scan/report.html?id=1cc214cee10f02d37359c0e3d04fd57899333c4b1eaa81489c74e5c2fa17c3a8-1324068153">http://www.virustotal.com/file-scan/report.html?id=1cc214cee10f02d37359c0e3d04fd57899333c4b1eaa81489c74e5c2fa17c3a8-1324068153</a><br />
VirusTotal Detections for Exploit Payload<br />
<a href="http://www.virustotal.com/file-scan/report.html?id=0e53832e1c36d34a3d05c05f73ebab22a74ade95c5f3b7d9f74fad4f56d10023-1324067892"> http://www.virustotal.com/file-scan/report.html?id=0e53832e1c36d34a3d05c05f73ebab22a74ade95c5f3b7d9f74fad4f56d10023-1324067892</a></p>
<p>The exploit payload possesses properties of targeted malware but is being served by an exploit of a popular, public website. The working theory for this anomaly relates to Amnesty International as a human rights non-governmental organization. To explain, certain countries use zero day exploits and other techniques to gain electronic information about the activities of human rights activists. Of course, a subset of these activists are too smart to click on links in even well-worded spearphishing emails. But what if you compromised a website frequented by these activists (e.g., Amnesty International)? Then your targets come to you. The context-specific damage potential is significant.</p>
<p>Amnesty International UK has been notified about the compromise.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.barracudalabs.com%2Fwordpress%2Findex.php%2F2011%2F12%2F22%2Fauthoritarian-regime-uses-human-rights-group-to-spy-on-activists%2F&amp;title=Human%20Rights%20Group%20Used%20to%20Spy%20on%20Activists" id="wpa2a_2"><img src="http://www.barracudalabs.com/wordpress/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.barracudalabs.com/wordpress/index.php/2011/12/22/authoritarian-regime-uses-human-rights-group-to-spy-on-activists/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Who can you trust?</title>
		<link>http://www.barracudalabs.com/wordpress/index.php/2010/05/20/who-can-you-trust/</link>
		<comments>http://www.barracudalabs.com/wordpress/index.php/2010/05/20/who-can-you-trust/#comments</comments>
		<pubDate>Thu, 20 May 2010 09:30:03 +0000</pubDate>
		<dc:creator>Barracuda Labs</dc:creator>
				<category><![CDATA[Email Security]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spear-phishing]]></category>

		<guid isPermaLink="false">http://www.barracudalabs.com/wordpress/?p=370</guid>
		<description><![CDATA[by Barracuda Labs In slasher movies, there&#8217;s often a scene where terrified teenagers try to trace the phone calls of a homicidal maniac only to discover that the phone calls are coming from inside the building. A recent spam case that was referred to the Lab reminded us of one of those scenes and underscored [...]]]></description>
			<content:encoded><![CDATA[<p><em>by Barracuda Labs</em></p>
<p>In slasher movies, there&#8217;s often a scene where terrified teenagers try to trace the phone calls of a homicidal maniac only to discover that the phone calls are coming from inside the building.</p>
<p>A recent spam case that was referred to the Lab reminded us of one of those scenes and underscored the fact that everyone should be suspicious of unsolicited emails. This is especially true of unsolicited emails that ask you to run something on your computer, no matter WHO they come from at any time.</p>
<p>In this particular case, the spam emails were sent to users within a medium-sized professional firm.  They were carefully crafted to appear to be an Adobe security update originally sent to the Assistant Director of Information Technology and then individually forwarded from her.   (Names and domains in the message have been changed.)</p>
<p>The bulk of the message looks like a security update from Adobe regarding vulnerability CVE-2010-0193. The linked executable actually is a malicious file that installs a Trojan backdoor program. The linked .PDF also contains a clickable link to the Trojan.  Adobe already has reported this spam campaign here:</p>
<p>http://blogs.adobe.com/psirt/2010/05/alert_adobe_security_update_em.html</p>
<p>What&#8217;s particularly interesting is just above the forwarded message.  The information about the sender of the email &#8211; Jane Doe, Assistant Director of Information Technology, JaneDoe@phished.com &#8211; is &#8216;real&#8217; data, most likely harvested from elsewhere on the Internet, and would appear to be normal to co-workers within her company.  Her email address is used in the body of the forwarded message as well, making it appear that it really was sent directly to Jane and then she is forwarding it along. Except that she isn&#8217;t.</p>
<p>The &#8216;From&#8217; field of the email has been spoofed (i.e., faked), something spammers easily can do. Instead, examination of the internal email headers reveals that the entire message was sent from a compromised computer in West Virginia.</p>
<p>It is common for spam to be sent with faked &#8216;From&#8217; data; however, this case takes that even a step further. The &#8216;From&#8217; name was chosen specifically in order to gain the trust of the users at phished.com who received the messages. This was a deliberate and targeted batch of spam, sometimes called &#8220;spear” phishing, which demonstrates just how clever the bad guys are and just how cautious we as users have to be.</p>
<p>Barracuda Spam Firewalls block these emails.</p>
<p>Below are various screenshots of the targeted attack in action.</p>
<div id="attachment_361" class="wp-caption alignleft" style="width: 288px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/05/adobepdf1.jpg"><img class="size-medium wp-image-361" title="The targeted email seemingly coming from inside the organization." src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/05/adobepdf1-278x300.jpg" alt="spam email message" width="278" height="300" /></a><p class="wp-caption-text">The targeted email seemingly coming from inside the organization. </p></div>
<div id="attachment_362" class="wp-caption alignleft" style="width: 310px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/05/adobepdf2.jpg"><img class="size-medium wp-image-362" title="The spoofed &quot;from&quot; address." src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/05/adobepdf2-300x252.jpg" alt="The spoofed &quot;from&quot; address." width="300" height="252" /></a><p class="wp-caption-text">The spoofed &quot;from&quot; address, which appears to be correct.</p></div>
<div id="attachment_363" class="wp-caption alignleft" style="width: 296px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/05/adobepdf3.jpg"><img class="size-medium wp-image-363" title="The .PDF mentioned in the email message that contains a malicious link." src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/05/adobepdf3-286x300.jpg" alt="The .PDF mentioned in the email message that contains a malicious link." width="286" height="300" /></a><p class="wp-caption-text">The .PDF mentioned in the email message that contains a malicious link.</p></div>
<div id="attachment_364" class="wp-caption alignleft" style="width: 310px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/05/adobepdf4.jpg"><img class="size-medium wp-image-364" title="Malicious file in action: the presumed software license agreement." src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/05/adobepdf4-300x281.jpg" alt="Malicious file in action: the presumed software license agreement." width="300" height="281" /></a><p class="wp-caption-text">Malicious file in action: the presumed software license agreement.</p></div>
<div id="attachment_365" class="wp-caption alignleft" style="width: 310px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/05/adobepdf5.jpg"><img class="size-medium wp-image-365" title="Malicious file in action: setup wizard." src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/05/adobepdf5-300x233.jpg" alt="Malicious file in action: setup wizard." width="300" height="233" /></a><p class="wp-caption-text">Malicious file in action: setup wizard.</p></div>
<div id="attachment_366" class="wp-caption alignleft" style="width: 310px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/05/adobepdf6.jpg"><img class="size-medium wp-image-366" title="Malicious file in action: accepting terms of the license agreement." src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/05/adobepdf6-300x233.jpg" alt="Malicious file in action: accepting terms of the license agreement." width="300" height="233" /></a><p class="wp-caption-text">Malicious file in action: accepting terms of the license agreement.</p></div>
<div id="attachment_367" class="wp-caption alignleft" style="width: 310px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/05/adobepdf7.jpg"><img class="size-medium wp-image-367" title="Malicious file in action: ready to install." src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/05/adobepdf7-300x233.jpg" alt="Malicious file in action: ready to install." width="300" height="233" /></a><p class="wp-caption-text">Malicious file in action: ready to install.</p></div>
<div id="attachment_368" class="wp-caption alignleft" style="width: 310px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/05/adobepdf8.jpg"><img class="size-medium wp-image-368" title="Malicious file in action: prompt to reboot." src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/05/adobepdf8-300x233.jpg" alt="Malicious file in action: prompt to reboot." width="300" height="233" /></a><p class="wp-caption-text">Malicious file in action: prompt to reboot.</p></div>
<div id="attachment_369" class="wp-caption alignleft" style="width: 310px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/05/adobepdf9.jpg"><img class="size-medium wp-image-369" title="Malicious file in action: execution complete." src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/05/adobepdf9-300x233.jpg" alt="Malicious file in action: execution complete." width="300" height="233" /></a><p class="wp-caption-text">Malicious file in action: execution complete.</p></div>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.barracudalabs.com%2Fwordpress%2Findex.php%2F2010%2F05%2F20%2Fwho-can-you-trust%2F&amp;title=Who%20can%20you%20trust%3F" id="wpa2a_4"><img src="http://www.barracudalabs.com/wordpress/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.barracudalabs.com/wordpress/index.php/2010/05/20/who-can-you-trust/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

