Computer Doctors

Technology Solutions, Service & Support

  • Home
  • Products
    • Desktops & Laptops
    • Servers
    • Security Cameras Solutions
  • Services
    • Technology Training Classes
    • Remote Support
    • Remote Backup Service
    • Computer Repair
    • Networking
    • Virus & Spyware Removal
    • Data Recovery
    • Helpful Links
  • Testimonials
  • Portfolio
  • News
  • Contact
    • About Us
  •  
  • Remote Support

Phishing scam that penetrated Wall Street just might work against you, too

December 1, 2014 by admin

Advanced tactics raise the bar on spearphishing attacks, making them harder to spot.

outlookPhishResearchers have uncovered a group of Wall Street-savvy hackers that has penetrated the e-mail accounts of more than 100 companies, a feat that has allowed them to obtain highly valuable plans concerning corporate acquisitions and other insider information.

FIN4, as the group is known, relies on a set of extremely simple tactics that in many cases has allowed them to remain undetected since at least the middle of 2013, according to a report published Monday from security firm FireEye. Members boast a strong command of the English language and knowledge of corporate finance and Fortune 500 culture. They use that savvy to send highly targeted spearphishing e-mails that harvest login credentials for Microsoft Outlook accounts. The group then uses compromised accounts of one employee, customer, or partner to send spearphishing e-mails to other company insiders. At times, the attackers will inject a malicious message into an ongoing e-mail discussion among multiple people, furthering their chances of success.

E-mails are sent from the accounts of people the target knows, and they discuss mergers, acquisitions, or other topics already in progress. The attackers often bcc other recipients to make it more difficult to detect the malicious e-mail. The messages appear to be written by native English speakers and often contain previously exchanged Microsoft Office documents that embed hidden malicious macros. This results in fraudulent e-mails that are extremely hard to detect, even by some people who have been trained to spot such phishing campaigns. Witness the following:

Subject: employee making negative comments about you and the company

From: [name]@[compromised company’s domain]

I noticed that a user named FinanceBull82 (claiming to be an employee) in an investment discussion forum posted some negative comments about the company in general (executive compensation mainly) and you in specific (overpaid and incompetent). He gave detailed instances of his disagreements, and in doing so, may have unwittingly divulged confidential company information regarding pending transactions. I am a longtime client and I do not think that this will bode well for future business. The post generated quite a few replies, most of them agreeing with the negative statements. While I understand that the employee has the right to his opinion, perhaps he should have vented his frustrations through the appropriate channels before making his post. The link to the post is located here (it is the second one in the thread):

http://forum./redirect. php?url=http://%2fforum%2fequities%2f375823902%2farticle.php\par

Could you please talk to him?

Thank you for the assistance,
[name]

FireEye researchers said FIN4 members have compromised the accounts of C-level executives, legal counsel, regulatory and compliance personnel, scientists, and advisors of more than 100 companies. About 80 of them are publicly traded companies, while the remaining 20 are Wall Street firms that advise corporations on legal or securities matters or possible or pending mergers and acquisitions. As a result, the group stood to make a windfall if it used the insider information to buy or sell stocks before the information became widely known.

“Our visibility into FIN4’s activities is limited to their network operations,” FireEye researchers Barry Vengerik, Kristen Dennesen, Jordan Berry, and Jonathan Wrolstad wrote. “We can only surmise how they may be using and potentially benefiting from the valuable information they are able to obtain. However one fact remains clear: access to insider information that could make or break stock prices for dozens of publicly traded companies could surely put FIN4 at a considerable trading advantage.”

Embedded in the previously stolen documents are Visual Basic Applications (VBA) macros that prompt readers to enter the Outlook user names and passwords. The scripts then funnel the credentials to servers controlled by the attackers. In other, earlier cases, the spearphishing e-mails contained links to fake Outlook Web App login pages that prompted visitors to enter their passwords. Some of the attacks FireEye observed targeted multiple parties inside law firms, consultancies, and corporations as they discussed particular pending business deals. In one instance, attackers used previously acquired access to e-mail accounts at an advisory firm to harvest information being exchanged about an acquisition under consideration involving one of its clients. The attackers used a compromised account belonging to the advisory firm to compromise the company, which FireEye identified only as Public Company A.

Read the full article here… http://arstechnica.com/security/2014/12/phishing-scam-that-penetrated-wall-street-just-might-work-against-you-too/

Credit – Dan Goodin, Arstechnica

Filed Under: Computer Doctors News, Security

Search Our Site

Latest News

Congratulations to area Graduates!

Happy Mother’s Day

9 Tips to Stay Safe When Shopping Online

Testimonials

"I took my SLOW laptop in and the next day it was ready to pick up. They removed lots of gremlins and cobwebs. Now my machine is as fast as brand new! I highly recommend them!" - Ben, NOVA Video
  • Email
  • Facebook
  • RSS

Computer Doctors
Technology Solutions, Service, & Support

Contact Information

Computer Doctors of Richland Center, LLC
122 W. Court Street
Richland Center, WI 53581

Phone: 608.647.5986
E-mail: info@rccomputerdrs.com

Office Hours

Monday - Friday - 8:30am - 5:00pm
Saturday & Sunday by Appointment

  • Email
  • Facebook
  • RSS
Return to top of page

Computer Doctors of Richland Center, LLC · Copyright © 2025 · Webmaster