Technology Sectors

Market Sectors

New York Times promotion piece used as bait in a global ‘spoofing’ attack

NY Times promo

A nefarious cyber-attacker, taking advantage of The New York Times’ vaunted reputation for veracity, has used an online promotional piece pitching “TimesReader 2.0” as bait in a targeted “spoofing” attack, according to MessageLabs Intelligence, a part of Symantec’s hosted services unit.

“MessageLabs Intelligence tracked a new targeted attack yesterday [February 24, 2010] using emails pretending to be from the New York Times sending out its ‘Times Reader’ software hitting six different domains,” said an e-mail announcement from a public relations firm representing MessageLabs Intelligence.

According to Paul Wood, a senior analyst with MessageLabs Intelligence, if a recipient of the bogus e-mail message clicks on the attachment, a virus will be downloaded that will automatically begin capturing data from the victim’s key logger, and transmitting that data to a computer sitting in Denmark. No tell-tale signs appear on the victim’s computer screen, so he or she will not know they have been infected with the computer virus, said Wood.

If, for example, the victim was to visit his online banking Web site, and entered his user name and password, his individual keystrokes would be sent automatically to the computer in Denmark.

The e-mail attacks originated from an IP address in Greece, says MessageLabs. Wood said it was unclear if the computer in Greece had, in fact, been “captured” by another computer, perhaps in a different country. “We might never know if they are being controlled by a different computer, which is controlled by the bad guys,” he said.

The spoofing attacks appear to have hit six different domains – one was a public sector domain, one was a law firm, three were chemical companies and one was an online gambling company in the UK, said MessageLabs Intelligence. All six domains are current customers of Symantec. Wood says about 25 individual computers have been infected thus far in those six different organizations.

Apparently, the virus that is downloaded to a victim’s computer automatically extinguishes itself. “The malware times out in about an hour and deletes itself,” said Wood.

Wood says MessageLabs Intelligence has not been in touch with the operators of the computers in either Greece or Denmark. “Typically, we get in touch with the ISPs [Internet Service Providers], so they can contact their own customers,” he added.

At The New York Times, Martin Nisenholz, senior vice president for digital operations, said he was not yet aware of this alleged spoofing attack. GSN is awaiting further comment from the newspaper, based in New York City.

 

Upcoming Events

Event Details Dates of Event
Mission Command Jun 10 - 12
Cyber Securty Brainstorm Jun 11 - 11
EDGE Summit 2013 Jun 11 - 11
IPv6 Summit 2013 Jun 14 - 16
SANSFIRE 2013 Jun 15 - 22
Oak Ridge National Laboratory's 2nd Biosurveillance Symposium Jun 17
Biodetection Technologies 2013 Jun 18 - 19
Southwest Microwave Seminar Jun 18 - 18
Cyber Defense and Network Security Summit Jun 24 - 26
Vanguard Security & Compliance 2013 Jun 24 - 27
SANS Canberra 2013 Jul 1 - 13
Border Management & Technologies Summit Jul 2 - 5
SANS Rocky Mountain 2013 Jul 15 - 20
SANS Mumbai 2013 Jul 22 - 27
Cyber Security Brainstorm Jul 24 - 24
SANS San Francisco 2013 Jul 29 - Aug 3
SANS Boston 2013 Aug 5 - 10
Cyber Security for Government Aug 12 - 14
SANS Thailand 2013 Aug 19 - 31
SANS Virginia Beach 2013 Aug 19 - 30
Maritime Security 2013 West Aug 19 - 21
930gov: Strategic Buying at Year-End Showcase Aug 21 - 21
SANS Melbourne 2013 Sep 2 - 7
SANS Capital City 2013 Sep 3 - 8
US/Canada Border Conference Sep 12 - 13
Network Security 2013 Sep 14 - 23
Cyber Intelligence Europe Sep 17 - 19
EnergySec 9th Annual Security Summit Sep 17 - 19
iFSO International Facility Security Officer Conference Sep 17 - 19
International Facility Security Officer Conference Sep 17 - 19
DefendUSA Sep 19 - 20
ASIS Foundation Golf Tournament Sep 23 - 23
NCT: CBRNe Asia, 24-27 September 2013, Kuala Lumpur Sep 24 - 27
ASIS Foundation Night at ASIS 2013 Sep 26 - 26
SANS Bangalore 2013 Oct 14 - 26
SOS SANS October Singapore 2013 Oct 21 - Nov 2