Newsletters
The Enterprise Security Supersite NewsFactor Sites:       NewsFactor.com     Enterprise Security Today     CRM Daily     Business Report     Sci-Tech Today  
   
This ad will display for the next 20 seconds. Please click for more information, or scroll down to pass the ad, or Close Ad.
Home Network Security Viruses & Malware Hackers Security Solutions More Topics...
Vblock™ Systems:
Advanced converged infrastructure
increases productivity & lowers costs.

www.vce.com
Viruses & Malware
24/7/365 Network Uptime
Average Rating:
Rate this article:  
Security Alert: Beware of Tiffany Trojan on the Attack
Security Alert: Beware of Tiffany Trojan on the Attack

By Jennifer LeClaire
May 22, 2013 12:24PM

Bookmark and Share
"Don't open that attachment!" warns Sophos security analyst Graham Cluley. If you get an email appearing to be from world-famous jeweler Tiffany's, saying something like, "Kindly open to see export License and payment invoice attached," it likely contains a malicious Trojan horse, designed to infect and compromise your computer.
 


Malware writers are using a luxury name to hack into your computer. Security watchdog Sophos is reporting that e-mails coming from a Tiffany.com address and carrying the attachment copy.zip are looking to install a malicious Trojan horse on your PC.

"This may be a deliberate ploy on the part of the criminals behind the attack to tempt more people into opening the attachment," Graham Cluley, senior security analyst at Sophos, wrote in a blog post. "Of course, it's child's play to forge e-mail header information, and there is no suggestion that the messages were really sent by Tiffany's," the high-end jeweler known for its little blue gift boxes tied smartly with white ribbon.

"If anything," Cluley said, the folks at Tiffany's "are also victims of this campaign."

Check Your Zipper

We asked Richard Westmoreland, a security analyst at security-as-a-service provider SilverSky, to chime in on the latest Trojan to make headlines. He explained that most successful e-mail Trojans now hide their malicious payload within zip files and depend on social engineering to get the end user to execute it.

"Companies can't block zip file attachments because it would impact legitimate business, however, e-mail filtering with virus scanning should still be able to inspect the contents of unencrypted zip files," Westmoreland said.

"It is important to scan for viruses both at the e-mail gateway and on the users' workstations, but equally important to remind employees not to open files they were not already expecting. In situations where antivirus does not yet have signatures for the payload and an employee still mistakenly opens the file, the workstation will likely start exhibiting suspicious behavior and the compromise could be detected by a SOC that is monitoring that network."

Copy Cat Social Engineers

Westmoreland's colleague Evan Keiser, also a security analyst with SilverSky, told us the Tiffany & Co. Trojan is just another copy of Bredolab (recognized by Sophos security scans as Mal/BredoZp-B). It leverages a foothold the bad guys have within Tiffany's mail server for a decent infection campaign.

"I believe it was pretty smart to utilize Tiffany's, as most people actually waiting on jewelry from them probably have some seriously high-limit credit cards," he said. "Tiffany's mail server was used to send out spam with Bredolab attached."

We also caught up with Grace Zeng, a research analyst at SilverSky, to get her take on the new Trojan. She told us this is not a new trick. Security experts have already seen a large number of fake invoice or delivery notice e-mails from UPS, FedEx and Amazon that contain malware or lead to exploit kits. In her opinion, this Tiffany email is not disguised well. "Who would expect an export license from Tiffany & Company," she asked, "when an order invoice would be more enticing?" (continued...)

1  |  2  |  Next Page >

 

Tell Us What You Think
Comment:

Name:

skunk:

Posted: 2013-07-05 @ 8:07pm PT
thanks got one of these emails today



APC has an established a reputation for solid products that virtually pay for themselves upon installation. Who has time to spend worrying about system downtime? APC makes it easy for you to focus on business growth instead of business downtime with reliable data center systems and IT solutions. Learn more here.


 Viruses & Malware
1.   Lessons from Verizon's Threat Report
2.   Malware Targets Facebook Users
3.   OpenSSL Calls for More Support
4.   How, Why Heartbleed Got Its Name
5.   Android Apps Mine Virtual Currency


advertisement
Lessons from Verizon's Threat Report
Enterprises can learn a thing or two.
Average Rating:
Malware Targets Facebook Users
iBanking app spys on communications.
Average Rating:
Android Apps Mine Virtual Currency
Malware drains mobile phone battery.
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Network Security Spotlight
Tech Giants Fund Initiative To Prevent Future Heartbleeds
Can more funding prevent Heartbleed vulnerabilities in future open-source software? A new Core Infrastructure Initiative at the Linux Foundation is attempting to find out.
 
What Verizon's Data Breach Report Can Teach Enterprises
It’s probably not a jaw-dropper, but cyberespionage is officially on the rise. And the use of stolen or misused credentials is still the leading way the bad guys gain access to corporate information.
 
Top Cyberthreats Exposed by Verizon Report
Beyond Heartbleed, there are cyberthreats vying to take down enterprise networks, corrupt smartphones, and wreak havoc on businesses. Verizon is exposing these threats in a new report.
 

Navigation
Enterprise Security Today
Home/Top News | Network Security | Viruses & Malware | Hackers | Security Solutions | Mobile Security | Disaster Recovery | Windows Security
Data Security | EST Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2014 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.