Below is an advisory from the Center for Internet Security about - TopicsExpress



          

Below is an advisory from the Center for Internet Security about the likelihood of malicious actors using the Syrian crisis as a basis for disguising spam and phishing attacks. As mentioned in the advisory, taking advantage of disasters and other major news events is a very common tactic used in these types of email attacks Cyber Intel Advisory: Malicious Actors Using Syrian Crisis as Basis for Spam Campaigns 11 September 2013 Integrated Intelligence Center Multi-State Information Sharing and Analysis Center The Risk: It is likely that the Syrian crisis will become a source of malicious spam over the next several days, in light of the recent attention focused on the Syrian crisis, including media interviews with US President Barack Obama and Syrian President Bashar al-Assad. The Center for Internet Security (CIS) recommends that users exhibit caution when responding to requests for donations or viewing unsolicited emails or websites purporting to contain information regarding the Syrian crisis. Malicious spam taking advantage of a major new event is a common occurrence. The Threats: Cyber security experts from Symantec and others have already identified spam taking advantage of the escalating crisis in Syria. § Malicious actors are sending phishing emails containing malware. One email links to a falsified CNN article with the title “The United States Began Bombing!” If a user clicks on the link, the Blackhole exploit kit will be executed. The Blackhole exploit kit is used to discover vulnerabilities on a system and deliver malware. Another email containing an attachment referencing the chemical attack in Syria exploits a publicized vulnerability to install a backdoor. Clicking links or opening attachments can infect a victim’s computer, furthering other malicious activity such as keystroke logging. § Malicious actors are sending spam emails calling for donations to the Red Cross and Red Crescent organizations. The emails link to the British Red Cross site, but request that donations above a certain value be sent via money transfer to an email address impersonating the British Red Cross.
Posted on: Fri, 13 Sep 2013 12:52:58 +0000

Trending Topics



Recently Viewed Topics




© 2015