All the latest UK technology news, reviews and analysis

Cyber criminals polish marketing skills for targeted attacks

by Shaun Nichols

26 Jul 2011

Be the first to comment

  • Tweet this

Sophisticated marketing and social engineering tactics are helping to change the face of cyber crime, according to the latest quarterly report from security firm IID.

Practices such as targeted phishing attacks and spam campaigns are benefiting from improved marketing techniques and tricks, the firm said.

IID president and chief technology officer Rod Rasmussen told V3 that criminals increasingly rely on compromised accounts to spread attacks to additional targets within an organisation.

He explained that in many cases, an attacker will target staff in strategic roles, such as a human resources manager, and then use the reputation of that stolen account to increase the likelihood of successful attacks on other employees.

"Because this is going on, you are getting communications from an account that you know and trust," he said. "It is always good to ask. Pick up the phone and make a call if something weird is going on."

Underworld interest in accessing that information has also increased lately. Rasmussen explained that online crime forums which previously dealt only in stolen credit card numbers have begun to trade in online account credentials.

The IID executive said that, along with making targeted attacks more effective, a compromised account can be used to break into other accounts owned by the same user.

"It is a cascading effect in a way. One compromise leads to another compromise which leads to even more compromises," Rasmussen said. "A lot of the people doing this are not that sophisticated, but they have access to information."

Criminals can likewise use the stolen credentials from one site to take over additional accounts on other sites because many people reuse their account names and passwords.

"It is not just your password that is important to protect, it is your username as well," Rasmussen said. "That is being driven home as a hard lesson these days."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

40%

0%

10%

50%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Business Development Executive

A Multi-national data analytic's and cloud computing...

C# Developer

A multi-national software solutions organisation are...

UI Application Designer

A multi-national software solution provider are looking...

Service Delivery Manager

Service Delivery Manager, Customer Service, PCT, Primary...

To send to more than one email address, simply separate each address with a comma.