Monthly Archives: August 2017

Check Your Spam?

As we noted yesterday, Jimmy Kimmell poked fun at the President’s Homeland Security Advisor for opening and responding to a spam email.  But is it really so unusual to interact with spam?  Today we filed our annual insurance audit.  Where’s my important confirmation from the insurance company?  Or, there it is — in my spam folder!

Luckily, I use SP Guard.  I have no concerns about this being a dangerous email because SP Guard identifies it as a real email from Hartford Insurance.

Spearphishing “Prank” Fools White House Officials

As reported by CNN and others, a UK prankster was able to trick Tom Bossert, the White House DHS Advisor, and Anthony Scaramucci, the then White House Communications Director. The prankster sent Bossert an email pretending to be Jared Kushner. The prank email to Scaramucci pretended to be from former Chief of Staff Reince Priebus.

This is from the Kushner-Bossert email thread:

Jimmy Kimmel, the ABC TV late night host, noted that the email said, “SUSPECTED_SPAM,” yet Bossert took the bait.

Bossert’s actions show the deceptive power of a well-crafted email. The prankster used facts that he discovered about Bossert and Kushner (in this case, that they had spent time together in Iraq) to create a credible deception story.  With this fact, the prankster was able to trigger the Vishwanath triad of perceived relevance, urgency clues and habit — despite the “SUSPECTED_SPAM” notation.  While it is easy to point a finger at Bossert, what does “Suspected spam” actually mean?  It is a warning of danger or it is a filter’s best guess as to relevance?  Or both?  How often do you check your spam folder for emails that shouldn’t be in spam? How often are you instructed to check your spam folder for confirmation emails? How useful is a spam warming?

Phish One – Compromise One Million

The  Hacker News is reporting on a spearphishing attack that has compromised over 1 million people.

How could this happen?  Over one million users use the popular chrome extension “Web Developer.” The bad guys spearphished the developer of “Web Developer” and then used the access they gained from spearphishing to modify “Web Developer” and push the modified code to over 1 million users.  The malicious version of “Web Developer” turned the victim’s web browser into an advertising nightmare by injecting ads on web pages.  It took several hours for the real developer of “Web Developer” to correct the problem and issue an update.  The bad guys had the potential to earn substantial ad commissions during the period that “Web Developer” was compromised.  What else they did is not known.  The bad guys could have done all sorts of things — even stealing passwords. The Hacker News article offers defensive advice for users of “Web Developer.”

 

WannaCry Hero Arrested

Marcus Hutchins is the 23 year old cybersecurity researcher who is credited with finding the killswitch to the WannaCry ransomware attack.

Marcus Hutchins

He was arrested yesterday (August 2, 2017) at the airport when he was preparing to leave the U.S. after attending the DefCon hacking conference in Las Vegas.  His arrest is reported on Motherboard.

The July 11, 2017,  Indictment alleges that Hutchins was involved with the Kronos banking trojan. Of course, Kronos malware can only do evil if it is installed on the target systems.  Like so much malicious software, Kronos is installed through phishing email attacks.