Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

August 16th, 2011, 15:01 GMT · By

Gmail Users Still Targeted in Chinese Spear Phishing Attacks

SHARE:

Adjust text size:


Government and military workers targeted in Gmail spear phishing attacks
Enlarge picture
Security researchers warn that spear phishing attacks targeting the personal Gmail accounts of people working for the military, government agencies or contractors, continue.

"Once compromises happen and are covered in the news, they do not disappear and attackers don't give up or stop. They continue their business as usual," writes independent security researcher Mila Parkour.

Parkour, who played an important role in investigating the original wave of attacks in June, analyzed a new campaign that generates emails posing as account suspension notifications.

The subject of the emails is "CNAS Report Calls Declining Satellite Capabilities National Security Concern," the title of a real press release from the Center for a New American Security (CNAS).

The email claims the recipient's account was suspended for unusual activity that may involve handling a large quantity of email over POP or IMAP, sending a large number of undeliverable messages, using browser extensions that automate authentication, leaving multiple instances of Gmail open and others.

The email contains a login form and instructs users to authenticate in order to re-activate their account. The recipient's address is already filled into the form.

Parkour created a dummy account, filled it in with email messages that attackers would be interested in, including some in Chinese, and submitted the login details for it via the form.

The stolen passwords were sent to a location on a legit but compromised website. In less than two hours the attackers accessed the account from a Tor exit node in the Netherlands, showing that they go to great lengths to cover their tracks.

"Google are aware of this, there is not much they can do to prevent these from coming in but I am sure they are trying. If you are concerned about your account safety, please use two-factor authentication and change your passwords often," Parkour advises.

TELL US WHAT YOU THINK:

1,525 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Yahoo and Hotmail Users also Targeted in Sophisticated Webmail Attacks

Government Officials and Political Activists Targeted in Gmail Spear Phishing Attack

House Rep Questions McAfee over Shady RAT Implications

READER COMMENTS:


Comment #1 by: gab7 on 20 Aug 2011, 14:34 UTC reply to this comment

I think that they are completely off base, and from my personal findings:
The code writer of Googles .mht extension, used in their web page download extension,,,is the same person who wrote the code framework for genetic programming. (if you dont know... Google it!)
anyhow! this particular file structure allows code to manipulate itself..by itself. I wrote a paper on it . If interested contact me at:
gkellerman7@gmail.com
-China NO!~

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM