search
Biztech2

HOME  / NEWS / SECURITY / CYBERCRIMINALS USE SOCIAL ENGINEERING EMAILS TO PENETRATE CORPORATE NETWORKS

Cybercriminals Use Social Engineering Emails To Penetrate Corporate Networks

by Biztech2.com Staff 25th September, 2012 in Security

   

FireEye, Inc. has announced the release of "Top Words Used in Spear Phishing Attacks to Successfully Compromise Enterprise Networks and Steal Data," a report that identifies the social engineering techniques cybercriminals use in email-based advanced cyber attacks. According to the report, the top words cybercriminals use create a sense of urgency to trick unsuspecting recipients into downloading malicious files. The top word category used to evade traditional IT security defenses in email-based attacks relates to express shipping.

According to recent data from the FireEye "Advanced Threat Report," for the first six months of 2012, email-based attacks increased 56 percent. Email-based advanced cyber attacks easily bypass traditional signature-based security defenses, preying on naïve users to install malicious files.

"Cybercriminals continue to evolve and refine their attack tactics to evade detection and use techniques that work. Spear phishing emails are on the rise because they work," said Ashar Aziz, Founder and CEO, FireEye. "Signature-based detection is ineffective against these constantly changing advanced attacks, so IT security departments need to add a layer of advanced threat protection to their security defences."

"Top Words Used in Spear Phishing Attacks to Successfully Compromise Enterprise Networks and Steal Data," explains that express shipping terms are included in about one quarter of attacks, including "DHL", "UPS", and "delivery." Urgent terms such as "notification" and "alert" are included in about 10 percent of attacks. An example of a malicious attachment is "UPS-Delivery-Confirmation-Alert_April-2012.zip."

The report indicates that cybercriminals also tend to use finance-related words, such as the names of financial institutions and an associated transaction such as "Lloyds TSB - Login Form.html," and tax-related words, such as "Tax_Refund.zip." Travel and billing words including "American Airlines Ticket" and "invoice" are also popular spear phishing email attachment key words.

Spear phishing emails are particularly effective as cybercriminals often use information from social networking sites to personalise emails and make them look mostly authentic. When unsuspecting users respond, they may inadvertently download malicious files or click on malicious links in the email, allowing criminal access to corporate networks and the potential exfiltration of intellectual property, customer information, and other valuable corporate assets.

The report highlights that cybercriminals primarily use zip files in order to hide malicious code, but also ranks additional file types, including PDFs and executable files.

"Top Words Used in Spear Phishing Attacks to Successfully Compromise Enterprise Networks and Steal Data" is based on data from the FireEye Malware Protection Cloud, a service shared by thousands of FireEye appliances around the world, as well as direct malware intelligence uncovered by its research team. The report provides a global view into email-based attacks that routinely bypass traditional security solutions such as firewalls and next-generation firewalls, IPS, anti-virus and gateways.

Tags: Cybercriminal, Cybercrime, Social, Corporate Networks, Threat

   

« Previous Story

ArrayShield To Provide Add-On...

« Next Story

Bitdefender Delivers...

POST YOUR COMMENTS

COMMENTS

There are no comments on this article yet. Why don't you post one?

Low quality building materials, violations blamed in Bangladesh disaster

#

A government investigation found that 'extremely' poor quality construction materials and a series of violations caused the collapse of a garment factory building in Bangladesh that has been called the worst garment-industry disaster in history, the committee head said Thursday.

Pay more for milk in Maharashtra from 25 May

#

Milk will become dearer in Maharashtra from 25 May, with the state government on Wednesday deciding to hike prices between Rs 2 and Rs 3 per litre.

Remorseful Warner insists he had to defend himself

#

Warner, who turns up for the Delhi Daredevils in the IPL, was found guilty of breaching Cricket Australia's code of behaviour and fined USD 5,600.

MORE NEWS

MORE IN SECURITY

Security Is The New Business Enabler

22nd May, 2013 by Sharon D'Souza

Vic Mankotia, VP - Security, Asia Pacific & Japan, CA Technologies shares how...

Read more

Trend Micro Ramps Up Its Cloud Security Optimised For AWS

21st May, 2013 by Biztech2.com Staff

Trend Micro Deep Security as a Service provides security capabilities delivered...

Read more

Data, Not Device, Is The New Security Focus

20th May, 2013 by Aletta D'cruz

Vishal Gupta, CEO, Seclore, explains that changing technology today demands...

Read more

Well-Managed Security Is An Asset

17th May, 2013 by Harry Cheung

Enterprises cannot ignore data security in the new connected world. All...

Read more

Sophos Announces Unified Threat Management Connected

15th May, 2013 by Biztech2.com Staff

This release introduces expanded UTM managed endpoint protection with Web in...

Read more