Douglas Schweitzer's picture
Douglas Schweitzer

The Security Sector

Gone Phishing...again

Looks like phishers are still at it, only now the targets are executives and they're being lured with "promise" of a subpoena. The problem is that once they follow the provided link in the email message, they're not really being directed to a federal court site, although the name "uscourts.com" may lead them to believe otherwise (perhaps because there really is a "uscourts.gov").  They're brought to a site where they're instructed to download a plug-in so that they'll be able to read their subpoena. Unfortunately, in reality the plug-in is malware.

I read in an article by Robert McMillan  "CEO-phishing scam fires up anew"  that "several thousand" executives fell for the trick and downloaded malicious software. Everyone - executive included - has to remember that subpoenas are not delivered via email.

The good news is that experts were able to take down the first of these phishing web sites but the bad news is that another one simply appeared on Wednesday.  I guess these guys must really have it in for CEOs and company executives, because there are few of these people to victimize when compared to other phishing schemes targets. Maybe that's why antivirus companies aren't blocking the latest version of this malware (as per John Bambenek, security researcher at the University of Illinois at Urbana-Champaign, quoted in the article).    

What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?