Home > Security News > PDF spam reemerges in some inboxes
Security News:
EMAIL THIS

PDF spam reemerges in some inboxes

By Robert Westervelt, News Editor
28 Jan 2008 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Some security researchers were scratching their heads when PDF spam nearly disappeared last summer, but now at least one firm, MX Logic, said it is tracking the reemergence of the format showing up in unwanted messages.

It could be somebody testing the waters or it could be the calm before the storm.
Sam Masiello,
director of threat management, MX Logic

Sam Masiello, director of threat management at Englewood, Colo.-based MX Logic, an antispam and managed services vendor, said PDF spam accounted for less than 0.5% of global spam volume last week. However, he said the reemergence of PDFs indicates spammers may be trying to test the file format against some spam filters.

"It could be somebody testing the waters or it could be the calm before the storm," Masiello said. "Generally your smaller, more localized attacks are less likely to be detected, but in this case it was obvious based on the subject lines that it was suspicious."

PDF spam emerged in July as a result of a tweak to the Storm Trojan, according to some security researchers. The PDF file format is widely used by businesses and as a result, security researchers were intrigued by the new method. Spam filtering vendors rapidly developed a way to detect the unwanted messages and help determine legitimate PDF files. Within a month of the PDF spam discovery, security firms said the levels of the file format almost completely disappeared.

Previous PDF spam contained messages for a pump and dump stock scheme. Masiello said the PDF spam discovered last week is easily detectable since it contains advertisements for a variety of pharmaceuticals – typical in most spam messages. Most businesses will have no problem determining a legitimate PDF file, he said.

In addition to the PDF spam, Storm continues to dominate most unwanted messages, according to Masiello. A Valentine's Day variant of Storm came out about two weeks ago, plaguing some inboxes. The Storm Valentine message contains a malicious URL. If the URL is clicked on by the recipient, the victim downloads an executable file and is infected, according to researchers at the SANS Internet Storm Center.

Spam, attack trends:

New rootkit threatens Windows users: A rootkit discovered in the wild has silently infected about 5,000 victims' machines, according to a warning issued by Symantec security researchers.

Happy Valentine's Day from the Storm Trojan: Controllers of the Storm Trojan are using the holiday theme to trick users into downloading the malware

Spammers tweak Storm to push PDF spam, less image spam In July, the Storm Trojan was generating PDF files to escape detection from antivirus software and trick employees with emails that look like business letters>

Masiello said spammers are also turning to stealthier methods of infection. A master boot record (MBR) rootkit was discovered earlier this month by security researchers who said it takes control of a system by silently overwriting the MBR with its own code. The master boot record is an important part of partitioned storage on a computer's hard disk.

The MBR rootkit was originally discovered by security researcher Matt Richard of Verisign's iDefense labs. Richard said the first attacks started in December. As many as 5,000 machines have been infected.

Masiello said malicious code in 2008, being delivered by spam, is showing early signs of furthering the trend of blended threats from attackers to trick and infect unsuspecting victims. In addition Zombie machinesPill spam, viruses, stock pump and dump spams.

"This model of the blended threat I think is still in its early stages partly because the methods in which people are being infected are still continuing to evolve," Masiello said. "Today, the user doesn't have to go to a malicious Web site or open a file attachment anymore to get infected."



Tags: Malware, Viruses, Trojans and SpywareEmail and Messaging Threats (spam, phishing, instant messaging)VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Malware, Viruses, Trojans and Spyware
Malware in Google attacks uses spaghetti code
Preparing for future security threats, evolving malware
Facebook attacks prompt investments in social networking security
Another PDF attack targets Adobe zero-day vulnerability
Security report finds rise in banking Trojans, adware, fewer viruses
How to prevent rogue antivirus programs in the enterprise
How to stop keylogging malware with more than basic antivirus software, firewalls
Conficker-infected machines now number 7 million, Shadowserver finds
FBI estimates rogue antivirus losses exceeding $150 million
Security researchers continue hunt for Conficker authors

Email and Messaging Threats (spam, phishing, instant messaging)
Chinese hacker attacks target Google Gmail accounts, top tech firms
PDF attack code complicates security analysis, skirts detection
Panda warns of American Express phishing scam
Active PDF attacks target Reader, Acrobat zero-day vulnerability
Yahoo login credentials at risk to hijacking attack
The world's top 5 riskiest domains
How to secure a .pdf file
Top spammer gets four years in jail for stock fraud scheme
New Zeus spam poses as Social Security statements
Messaging security risks have upper hand on solutions
Email and Messaging Threats (spam, phishing, instant messaging) Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
bot worm  (SearchSecurity.com)
directory traversal  (SearchSecurity.com)
government Trojan  (SearchSecurity.com)
Kraken  (SearchSecurity.com)
man in the browser  (SearchSecurity.com)
polymorphic malware  (SearchSecurity.com)
RAT (remote access Trojan)  (SearchSecurity.com)
RavMonE virus  (SearchSecurity.com)
RFID virus  (SearchSecurity.com)
Rock Phish  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2010, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts