Home > Security News > PDF spam reemerges in some inboxes
Security News:
EMAIL THIS

PDF spam reemerges in some inboxes

By Robert Westervelt, News Editor
28 Jan 2008 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Some security researchers were scratching their heads when PDF spam nearly disappeared last summer, but now at least one firm, MX Logic, said it is tracking the reemergence of the format showing up in unwanted messages.

It could be somebody testing the waters or it could be the calm before the storm.
Sam Masiello,
director of threat management, MX Logic

Sam Masiello, director of threat management at Englewood, Colo.-based MX Logic, an antispam and managed services vendor, said PDF spam accounted for less than 0.5% of global spam volume last week. However, he said the reemergence of PDFs indicates spammers may be trying to test the file format against some spam filters.

"It could be somebody testing the waters or it could be the calm before the storm," Masiello said. "Generally your smaller, more localized attacks are less likely to be detected, but in this case it was obvious based on the subject lines that it was suspicious."

PDF spam emerged in July as a result of a tweak to the Storm Trojan, according to some security researchers. The PDF file format is widely used by businesses and as a result, security researchers were intrigued by the new method. Spam filtering vendors rapidly developed a way to detect the unwanted messages and help determine legitimate PDF files. Within a month of the PDF spam discovery, security firms said the levels of the file format almost completely disappeared.

Previous PDF spam contained messages for a pump and dump stock scheme. Masiello said the PDF spam discovered last week is easily detectable since it contains advertisements for a variety of pharmaceuticals – typical in most spam messages. Most businesses will have no problem determining a legitimate PDF file, he said.

In addition to the PDF spam, Storm continues to dominate most unwanted messages, according to Masiello. A Valentine's Day variant of Storm came out about two weeks ago, plaguing some inboxes. The Storm Valentine message contains a malicious URL. If the URL is clicked on by the recipient, the victim downloads an executable file and is infected, according to researchers at the SANS Internet Storm Center.

Spam, attack trends:

New rootkit threatens Windows users: A rootkit discovered in the wild has silently infected about 5,000 victims' machines, according to a warning issued by Symantec security researchers.

Happy Valentine's Day from the Storm Trojan: Controllers of the Storm Trojan are using the holiday theme to trick users into downloading the malware

Spammers tweak Storm to push PDF spam, less image spam In July, the Storm Trojan was generating PDF files to escape detection from antivirus software and trick employees with emails that look like business letters>

Masiello said spammers are also turning to stealthier methods of infection. A master boot record (MBR) rootkit was discovered earlier this month by security researchers who said it takes control of a system by silently overwriting the MBR with its own code. The master boot record is an important part of partitioned storage on a computer's hard disk.

The MBR rootkit was originally discovered by security researcher Matt Richard of Verisign's iDefense labs. Richard said the first attacks started in December. As many as 5,000 machines have been infected.

Masiello said malicious code in 2008, being delivered by spam, is showing early signs of furthering the trend of blended threats from attackers to trick and infect unsuspecting victims. In addition Zombie machinesPill spam, viruses, stock pump and dump spams.

"This model of the blended threat I think is still in its early stages partly because the methods in which people are being infected are still continuing to evolve," Masiello said. "Today, the user doesn't have to go to a malicious Web site or open a file attachment anymore to get infected."



Tags: Malware, Viruses, Trojans and SpywareEmail and Messaging Threats (spam, phishing, instant messaging)VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Malware, Viruses, Trojans and Spyware
Increase in Gumblar backdoors poses FTP credential problems
Hackers to sharpen malware, malicious software in 2010
iPhone worm Rickrolls jailbroken phones
Israeli Mossad add Trojan Horse to Syrian laptop
Schneier-Ranum Face-Off: Is antivirus dead?
Modern malware, stealthy botnets, adapt quickly, expert says
Computer worm infections up, scareware antivirus down, Microsoft says
Web-based attacks skyrocket, pirating sites surge, security firms say
Mini guide: How to remove and prevent Trojans, malware and spyware
Kaspersky system analyzes malicious URLs on Twitter for malware

Email and Messaging Threats (spam, phishing, instant messaging)
Messaging security risks have upper hand on solutions
Web-based attacks skyrocket, pirating sites surge, security firms say
Pushdo botnet uses Facebook to spread malicious email attachment
Scareware report highlights successful business model
How to prevent phishing attacks with social engineering tests
Phishing protection begins with training, antiphishing evangelist
Phishing attacks to remain a major problem, say security experts
Barracuda acquires Purewire expanding Web security reach
FBI raids phishing crime ring, nearly 100 arrested
Massive phishing scheme affects Microsoft Hotmail accounts
Email and Messaging Threats (spam, phishing, instant messaging) Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
bot worm  (SearchSecurity.com)
directory traversal  (SearchSecurity.com)
government Trojan  (SearchSecurity.com)
Kraken  (SearchSecurity.com)
man in the browser  (SearchSecurity.com)
polymorphic malware  (SearchSecurity.com)
RAT (remote access Trojan)  (SearchSecurity.com)
RavMonE virus  (SearchSecurity.com)
RFID virus  (SearchSecurity.com)
Rock Phish  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts