Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Applications
    • Applications
    • Cybersecurity
    • IT Management
    • Networking

    Excel Latest Vehicle for Pump-and-Dump Spam

    Written by

    Brian Prince
    Published July 24, 2007
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      “Pump-and-dump” spammers have found a new package for their scam: Excel files.

      Commtouch researchers reported the appearance of pump-and-dump spam in Excel files for the first time on July 21. The spam promotes stocks in file attachments with names such as “invoice20202.xls,” “stock information-3572.xls” and “requested report.xls.”

      “Excel is a logical progression from older formats, and the spammers are always looking for something new to bypass anti-spam engines,” said Rebecca Steinberg Herson, senior director of marketing for Commtouch, in Sunnyvale, Calif.

      “It used to be spelling tricks, and then the anti-spam engines got more sophisticated and caught on; more recently, spammers have tried sending images, but after a while, many anti-spam engines developed the capability to block this method of spam. Then PDF … so the spammers needed a new format to try,” she said.

      Commtouch officials said they believe the Excel spam is being sent from zombie computers or machines that have previously been infected by Trojan-type malware. According to Nick Edwards, project manager for Cisco Systems IronPort, based in San Bruno, Calif., the stock volume for the stock promoted by the Excel scammers shot up from fewer than 1,000 shares traded as of the week of July 16 to over 40,000 shares on July 23. This also contributed to driving the price up from about 15 cents per share to 23 cents per share on July 23.

      /zimages/4/28571.gifClick here to read more about how spammers have switched to PDF attachments to get their messages through.

      “We definitely see Excel and other attachments as being a growing avenue for spam and viruses,” said Willy Leichter, director of product marketing for Tumbleweed Communications, headquartered in Redwood City, Calif. “End users have become so used to sharing files via e-mail and using Outlook as their de facto collaboration tool. But as weve seen before, e-mail wasnt designed around security, and its explosive growth and convenience make it a huge security target.”

      Malware writers have used Excel as a carrier for viruses in the past, Commtouch officials pointed out. A series of attacks during June and July 2006 exploited vulnerabilities in Microsoft software, including Excel, Microsoft Word and PowerPoint.

      Herson said spammers are creative and constantly on the lookout for effective ways to make money from their botnet infrastructure.

      /zimages/4/28571.gifHas there been a significant reduction in pump-and-dump spam? Click here to read more.

      “Spammers often first send out a trial balloon in a limited distribution, to see how well the new method works,” she said. “If they get a good response rate, then they start sending out bigger waves. So, if we start seeing more extensive use of this format, it indicates that the response rate to this pilot was satisfactory for the spammers.”

      Check out eWEEK.coms Security Center for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEKs Security Watch blog.

      Brian Prince
      Brian Prince

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×