Behold, the spear phish that just might be good enough to hook you

Enlarge (credit: Unbiassed)

To understand why Carbanak is one of the Internet’s most skilled and successful criminal groups, consider the recent spear-phishing campaign it used to infect computers in the hospitality and restaurant industries with malware that steals banking credentials.

One variation started with an e-mail threatening a lawsuit because a visitor got sick after eating at one of the company’s restaurants. To increase the chances the attached Microsoft Word document is opened, the attackers personally follow up with a phone call encouraging the recipient to open the booby-trapped file and click inside. The attacker calls back a half-hour later to check if the recipient has opened the document. The attacker immediately hangs up in the event the answer is yes.

Behind the scenes, macros embedded inside the Word document infect the employee’s computer with a trojan that surreptitiously takes screenshots and retrieves credit card data and other sensitive banking credentials. The trojan then attempts to infect other computers on the same network in an attempt to steal additional loot. And all because the attacker, who is halfway around the globe, made a compelling case that it was in the employee’s best interests to open the document and allow the embedded macro to run.

Read 4 remaining paragraphs | Comments

Ars Technica

Post Author: martin

Martin is an enthusiastic programmer, a webdeveloper and a young entrepreneur. He is intereted into computers for a long time. In the age of 10 he has programmed his first website and since then he has been working on web technologies until now. He is the Founder and Editor-in-Chief of BriefNews.eu and PCHealthBoost.info Online Magazines. His colleagues appreciate him as a passionate workhorse, a fan of new technologies, an eternal optimist and a dreamer, but especially the soul of the team for whom he can do anything in the world.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.