Social engineering - Targeted Malware Campaign Takes Social Engineering to New Heights - eWeek Security Watch

Targeted Malware Campaign Takes Social Engineering to New Heights

Written By
Brian Prince
Brian Prince
May 6, 2010
1 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

File this under interesting social engineering techniques.

According to Red Condor, attackers are blasting out e-mails with a thread of messages claiming to be about an important update from Adobe Systems that fixes a denial-of-service vulnerability. The e-mails of course do not contain an update; just malware.

But the most interesting part of the campaign is the way the attackers customized the message. The thread contains what appear to be the full names and e-mail addresses of people in higher positions in the recipient’s organization, added in an attempt to make the message look legitimate. The spoofed e-mail also appears to be from a fellow employee. Inside the e-mail are links to a PDF file containing update instructions for the patch, as well as an executable that Red Condor has identified as malware.

The good news is that the campaign is highly targeted and not widespread. While the company is not sure how the addresses in the e-mails were obtained, researchers said there are a number of possibilities, including that addresses were skimmed from Websites.

“This sophisticated campaign demonstrates the lengths scammers will go to get their e-mails past security so they can deploy malware on unsuspecting users’ systems,” Tom Steding, CEO of Red Condor, said in a statement. “The e-mail itself contains convincing language and appears to have already made it through chains of command at the victim’s company. Overall, it’s a convincing campaign that could be a significant threat if the message volume increases.”

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.