Feeds

If you see 'URGENT tax rebate download' in an inbox, kill it with fire

Top spear-phishing email phrases revealed

The essential guide to IT transformation

FireEye has put together a list of the most common words and phrases that appear in fake emails designed to infect corporate networks and steal data.

The security firm said that the list spotlights the social engineering techniques that feature as a key component of so-called spear phishing attacks. Hackers tend to use words that create a sense of urgency in a bid to trick unsuspecting recipients into downloading malicious files.

The top word category in email-based attacks relates to express shipping. Words such as "DHL", "UPS", and "delivery" featuring in a quarter of overall attacks. Urgent terms such as “notification” and “alert” are included in about 10 per cent of attacks. Some attacks mix and match terms from these two popular categories such as "UPS-Delivery-Confirmation-Alert_April-2012.zip", one example cited by FireEye.

Email-based attacks increased 56 per cent between Q1 2012 and Q2 2012, according to FireEye. The security firm claims these attacks often get through multiple layers of defence – including anti-virus, firewalls and intrusion prevention systems – to reach corporate desktops.

Cybercrooks and spies are also fond of finance-related words, such as the names of financial institutions and an associated transaction such as "Lloyds TSB - Login Form.html", and tax-related words, such as "Tax_Refund.zip". Travel and billing words including "American Airlines Ticket" and "invoice" are also popular spear phishing email attachment keywords.

FireEye warns that crooks often use phrases from social engineering sites to "personalise" booby-trapped emails and make them look more authentic.

Attackers primarily use zip files in order to hide malicious code, but other file types, including PDFs and executable files, also feature in attacks ultimately aimed at gaining access to corporate networks before stealing intellectual property, customer information, and other valuable data. It's hard to believe that executables, in particular, aren't routinely blocked at corporate email gateways, but FireEye's research suggests otherwise.

The study, Top Words Used in Spear Phishing Attacks to Successfully Compromise Enterprise Networks and Steal Data (PDF), is based on data from the FireEye Malware Protection Cloud, a service shared by thousands of FireEye appliances, as well as input from FireEye's research team. ®

Next gen security for virtualised datacentres

More from The Register

next story
Ice cream headache as black hat hacks sack Dairy Queen
I scream, you scream, we all scream 'DATA BREACH'!
Goog says patch⁵⁰ your Chrome
64-bit browser loads cat vids FIFTEEN PERCENT faster!
KER-CHING! CryptoWall ransomware scam rakes in $1 MEEELLION
Anatomy of the net's most destructive ransomware threat
NIST to sysadmins: clean up your SSH mess
Too many keys, too badly managed
Scratched PC-dispatch patch patched, hatched in batch rematch
Windows security update fixed after triggering blue screens (and screams) of death
Researchers camouflage haxxor traps with fake application traffic
Honeypots sweetened to resemble actual workloads, complete with 'secure' logins
Attack flogged through shiny-clicky social media buttons
66,000 users popped by malicious Flash fudging add-on
New Snowden leak: How NSA shared 850-billion-plus metadata records
'Federated search' spaffed info all over Five Eyes chums
Three quarters of South Korea popped in online gaming raids
Records used to plunder game items, sold off to low lifes
prev story

Whitepapers

5 things you didn’t know about cloud backup
IT departments are embracing cloud backup, but there’s a lot you need to know before choosing a service provider. Learn all the critical things you need to know.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Backing up Big Data
Solving backup challenges and “protect everything from everywhere,” as we move into the era of big data management and the adoption of BYOD.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?