'Artisanal spam': Carefully designed emails a new kind of cyberattack

Traditional spam email attacks follow a mass-market, "one-size-fits-all" logic: By sending the same message to as many targets as possible, a small minority of people will be tricked into sharing their passwords or downloading a malicious program.

But a new kind of spam attack is turning that logic on its head. So-called "artisanal spam" targets smaller groups of potential victims with painstakingly-crafted messages, with the aim of breaking through spam-filtering algorithms and achieving a higher rate of success.

Patrick Peterson, CEO of U.S. cyber-security firm Agari Data, says his company started noticing the attacks between six and nine months ago. Since then, he estimates these kinds of attacks have numbered "in the low hundreds," although he notes that it can be hard to track such relatively small attacks.

"It's just a continuation of a long-term trend we've seen around criminal innovation," Peterson told CBC News.

This new method of spamming, says Peterson, is more likely to avoid the spam filters built into most e-mail clients, and more likely to get criminals what they want — account credentials like usernames and passwords, as well as potential targets for malware attacks.

The French connection

The most notable incident so far, according to Peterson, took place on October 13, 2015. It targeted about 5,000 French users of Apple's popular iTunes music software, in a two-pronged attack designed to steal usernames and passwords, and possibly use those credentials to install malware on the victims' computers.

The criminal or criminals behind the attack "carefully curated" a French-language email, says Peterson, and specifically targeted email accounts based in France. That ensured that recipients would be more likely to read the email. The attackers also targeted users of smaller, local French internet service providers, whom Peterson says might not be targeted as frequently as users of major e-mail services like Gmail or Hotmail.

French Apple iTunes spam attack

A screenshot of an 'artisanal spam' e-mail attack designed to target French users of Apple's iTunes software. (Agari Data)

The goal was to maximize what Peterson calls the delivery rate: the number of targets who actually lay eyes on the malicious email.

"We saw the vast majority of these messages delivered to the victims," says Peterson. "We don't actually have statistics on how many of them either installed malware on their computers or gave away their iTunes credentials, but I can say that the delivery rate was far greater than your typical mass-market spam."

"It's very difficult nowadays to keep up in the cyber arms race." - Patrick Peterson, CEO, Agari Data

Like many other malicious e-mail attacks, the French incident convinced targets that their iTunes accounts were at risk if they didn't click on a link and enter their credentials. Unlike most big spam attacks, though, the perpetrators took the time to customise their messages.

"To be perfectly honest, it's just a question of good copy-writing skills and a lot of attention to detail so that [the spam] looks just like the original," says Peterson. "The reality is, it's not that difficult. It's just that historically, criminals have been able to blast billions of these, and if half the people didn't think it was authentic, the criminals didn't lose too much sleep because they had sent so many."

Protecting yourself from 'artisanal spam'

Because it's relatively easy to produce an authentic-looking spam message, Peterson says, internet users should never assume they can tell the difference. He suggests people maintain an air of skepticism when evaluating emails.

"If you were walking down the streets of Toronto and someone came up to you and claimed to be from your bank or your auto warranty with a problem, people know how to respond to that," says Peterson. "But for some reason, when someone plops something in their inbox pretending to be similar entities, people just believe it."

If an email attempts to bait you into clicking on an external link, Peterson recommends hovering your cursor over the hyperlink and checking to see if the destination URL is what it claims to be.

It's possible that users of smaller internet service providers are more at risk from these types of attack, added Peterson.

"It's very difficult nowadays to keep up in the cyber arms race. Even the largest providers with the most resources are struggling."

Share on Google Plus

About Unknown

My blog is the place to update the latest information on sports, science and technology ... If you found this article good, useful please the share for others to see, even if you want to design a ecommerce website or web edit or set a special plugin functionality, please contact us now (Information in the footer)
    Blogger Comment
    Facebook Comment

0 nhận xét:

Đăng nhận xét