Spear phishing: researchers work to counter email attacks that gain recipients’ trust

09 Jan 2013

1

The email resembled the organisation's own employee e-newsletter and asked recipients to visit a website to confirm that they wanted to continue receiving the newsletter. Another email carried an attachment it said contained the marketing plan the recipient had requested at a recent conference. A third email bearing a colleague's name suggested a useful website to visit.

None of these emails were what they pretended to be. The first directed victims to a website that asked for personal information, including the user's password. The second included a virus launched when the ''marketing plan'' was opened. The third directed users to a website that attempted to install a malicious program.

All three are examples of what information security experts at the Georgia Tech Research Institute (GTRI) say is the most challenging threat facing corporate networks today: ''spear phishing.''

Generic emails asking employees to open malicious attachments, provide confidential information or follow links to infected websites have been around for a long time. What's new today is that the authors of these emails are now targeting their attacks using specific knowledge about employees and the organizations they work for. The inside knowledge used in these spear phishing attacks gains the trust of recipients.

''Spear phishing is the most popular way to get into a corporate network these days,'' said Andrew Howard, a GTRI research scientist who heads up the organisation's malware unit. ''Because the malware authors now have some information about the people they are sending these to, they are more likely to get a response. When they know something about you, they can dramatically increase their odds.''

The success of spear phishing attacks depends on finding the weakest link in a corporate network. That weakest link can be just one person who falls for an authentic-looking email.

Latest articles

OpenAI Acquires Neptune to Fortify Training Infrastructure as Valuation Hits $500 Billion

OpenAI Acquires Neptune to Fortify Training Infrastructure as Valuation Hits $500 Billion

Amazon and Google Roll Out Joint Multicloud Service to Boost High-Speed Connectivity

Amazon and Google Roll Out Joint Multicloud Service to Boost High-Speed Connectivity

TRAI Cracks Down on Spam: Over 21 Lakh Fraud Numbers Disconnected; New Advisory Issued

TRAI Cracks Down on Spam: Over 21 Lakh Fraud Numbers Disconnected; New Advisory Issued

Google Expands Taiwan Presence With New AI Engineering Centre

Google Expands Taiwan Presence With New AI Engineering Centre

Maruti Suzuki Crosses 3 Crore Domestic Sales Milestone — A New Chapter in India’s Automotive Story

Maruti Suzuki Crosses 3 Crore Domestic Sales Milestone — A New Chapter in India’s Automotive Story

Alaska Airlines Resumes Operations Following Major Tech Outage

Alaska Airlines Resumes Operations Following Major Tech Outage

Tesla's New AI Chip: A Strategic Partnership with Samsung and TSMC, Not a Replacement for Nvidia

Tesla's New AI Chip: A Strategic Partnership with Samsung and TSMC, Not a Replacement for Nvidia

Uber Rebrands ‘Green’ as ‘Electric,’ Offers $4,000 Incentives to U.S. Drivers to Accelerate EV Adoption

Uber Rebrands ‘Green’ as ‘Electric,’ Offers $4,000 Incentives to U.S. Drivers to Accelerate EV Adoption

Jaguar Land Rover Cyberattack Estimated to Cost UK Economy $2.5 Billion

Jaguar Land Rover Cyberattack Estimated to Cost UK Economy $2.5 Billion

Business History Videos

History of hovercraft Part 3 | Industry study | Business History

History of hovercraft Part 3...

Today I shall talk a bit more about the military plans for ...

By Kiron Kasbekar | Presenter: Kiron Kasbekar

History of hovercraft Part 2 | Industry study | Business History

History of hovercraft Part 2...

In this episode of our history of hovercraft, we shall exam...

By Kiron Kasbekar | Presenter: Kiron Kasbekar

History of Hovercraft Part 1 | Industry study | Business History

History of Hovercraft Part 1...

If you’ve been a James Bond movie fan, you may recall seein...

By Kiron Kasbekar | Presenter: Kiron Kasbekar

History of Trams in India | Industry study | Business History

History of Trams in India | ...

The video I am presenting to you is based on a script writt...

By Aniket Gupta | Presenter: Sheetal Gaikwad

view more
View details about the software product Informachine News Trackers