Home > Security News > PDF spam reemerges in some inboxes
Security News:
EMAIL THIS LICENSING & REPRINTS

PDF spam reemerges in some inboxes

By Robert Westervelt, News Editor
28 Jan 2008 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Some security researchers were scratching their heads when PDF spam nearly disappeared last summer, but now at least one firm, MX Logic, said it is tracking the reemergence of the format showing up in unwanted messages.

It could be somebody testing the waters or it could be the calm before the storm.
Sam Masiello,
director of threat management, MX Logic

Sam Masiello, director of threat management at Englewood, Colo.-based MX Logic, an antispam and managed services vendor, said PDF spam accounted for less than 0.5% of global spam volume last week. However, he said the reemergence of PDFs indicates spammers may be trying to test the file format against some spam filters.

"It could be somebody testing the waters or it could be the calm before the storm," Masiello said. "Generally your smaller, more localized attacks are less likely to be detected, but in this case it was obvious based on the subject lines that it was suspicious."

PDF spam emerged in July as a result of a tweak to the Storm Trojan, according to some security researchers. The PDF file format is widely used by businesses and as a result, security researchers were intrigued by the new method. Spam filtering vendors rapidly developed a way to detect the unwanted messages and help determine legitimate PDF files. Within a month of the PDF spam discovery, security firms said the levels of the file format almost completely disappeared.

Previous PDF spam contained messages for a pump and dump stock scheme. Masiello said the PDF spam discovered last week is easily detectable since it contains advertisements for a variety of pharmaceuticals – typical in most spam messages. Most businesses will have no problem determining a legitimate PDF file, he said.

In addition to the PDF spam, Storm continues to dominate most unwanted messages, according to Masiello. A Valentine's Day variant of Storm came out about two weeks ago, plaguing some inboxes. The Storm Valentine message contains a malicious URL. If the URL is clicked on by the recipient, the victim downloads an executable file and is infected, according to researchers at the SANS Internet Storm Center.

Spam, attack trends:

New rootkit threatens Windows users: A rootkit discovered in the wild has silently infected about 5,000 victims' machines, according to a warning issued by Symantec security researchers.

Happy Valentine's Day from the Storm Trojan: Controllers of the Storm Trojan are using the holiday theme to trick users into downloading the malware

Spammers tweak Storm to push PDF spam, less image spam In July, the Storm Trojan was generating PDF files to escape detection from antivirus software and trick employees with emails that look like business letters>

Masiello said spammers are also turning to stealthier methods of infection. A master boot record (MBR) rootkit was discovered earlier this month by security researchers who said it takes control of a system by silently overwriting the MBR with its own code. The master boot record is an important part of partitioned storage on a computer's hard disk.

The MBR rootkit was originally discovered by security researcher Matt Richard of Verisign's iDefense labs. Richard said the first attacks started in December. As many as 5,000 machines have been infected.

Masiello said malicious code in 2008, being delivered by spam, is showing early signs of furthering the trend of blended threats from attackers to trick and infect unsuspecting victims. In addition Zombie machinesPill spam, viruses, stock pump and dump spams.

"This model of the blended threat I think is still in its early stages partly because the methods in which people are being infected are still continuing to evolve," Masiello said. "Today, the user doesn't have to go to a malicious Web site or open a file attachment anymore to get infected."



Sound Off! -   Be the first to post a message to Sound Off!


Tags: Spam and AntispamPhishingSpyware, Adware and TrojansViruses, Worms and Other MalwareVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts