Feeds

If you see 'URGENT tax rebate download' in an inbox, kill it with fire

Top spear-phishing email phrases revealed

Top three mobile application threats

FireEye has put together a list of the most common words and phrases that appear in fake emails designed to infect corporate networks and steal data.

The security firm said that the list spotlights the social engineering techniques that feature as a key component of so-called spear phishing attacks. Hackers tend to use words that create a sense of urgency in a bid to trick unsuspecting recipients into downloading malicious files.

The top word category in email-based attacks relates to express shipping. Words such as "DHL", "UPS", and "delivery" featuring in a quarter of overall attacks. Urgent terms such as “notification” and “alert” are included in about 10 per cent of attacks. Some attacks mix and match terms from these two popular categories such as "UPS-Delivery-Confirmation-Alert_April-2012.zip", one example cited by FireEye.

Email-based attacks increased 56 per cent between Q1 2012 and Q2 2012, according to FireEye. The security firm claims these attacks often get through multiple layers of defence – including anti-virus, firewalls and intrusion prevention systems – to reach corporate desktops.

Cybercrooks and spies are also fond of finance-related words, such as the names of financial institutions and an associated transaction such as "Lloyds TSB - Login Form.html", and tax-related words, such as "Tax_Refund.zip". Travel and billing words including "American Airlines Ticket" and "invoice" are also popular spear phishing email attachment keywords.

FireEye warns that crooks often use phrases from social engineering sites to "personalise" booby-trapped emails and make them look more authentic.

Attackers primarily use zip files in order to hide malicious code, but other file types, including PDFs and executable files, also feature in attacks ultimately aimed at gaining access to corporate networks before stealing intellectual property, customer information, and other valuable data. It's hard to believe that executables, in particular, aren't routinely blocked at corporate email gateways, but FireEye's research suggests otherwise.

The study, Top Words Used in Spear Phishing Attacks to Successfully Compromise Enterprise Networks and Steal Data (PDF), is based on data from the FireEye Malware Protection Cloud, a service shared by thousands of FireEye appliances, as well as input from FireEye's research team. ®

Combat fraud and increase customer satisfaction

Whitepapers

Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Mainstay ROI - Does application security pay?
In this whitepaper learn how you and your enterprise might benefit from better software security.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.