A CEO As A Cybercrime Target

author-image
DQC News Bureau
New Update

All it takes is one click of the mouse on a seemingly internal e-mail.
With that, the CEO of a customer company could unwittingly enable a
cyber-criminal to mine his hard drive for credit card numbers, passwords to
corporate databases or other proprietary information

Advertisment

If credit card phishers are the carpet bombers of computer crime, C-level
attackers are the snipers. They mine information from a relatively small number
of wealthy or high-status individuals in positions of power. They are after
corporate and personal data, both of which can be extremely lucrative.

They can use that information to wreak havoc elsewhere, or they can sell it
for profit. These types of targeted C-level attacks are rare, but they're on the
rise, and they're sophisticated enough to make the average IT manager's blood
run cold.

Following the money

C-level attacks “started out about a year ago in very low numbers but have
been ramping up since,” said Matt Sargeant, Senior Antispam Technologist,
MessageLabs Ltd, a security services provider in New York. There are three
reasons for that, observers say.

Advertisment

Executives are reading their own e-mails and using their own PC applications
rather than leaving those tasks to administrative assistants; they're traveling
more with less-secure digital devices in tow; and, like everyone else, they're
exploring the power of social networks, inadvertently exposing details that
could make them the targets of criminals.

The results can be chilling (read box). An IT manager at a Fortune 500
financial institution shared that his company, too, recently fought off a
C-level attack. In this instance, a bank executive's laptop was hacked while he
was working from home. The hacker captured passwords and log-ins and tried to
access some of the bank's accounts.

The attempt, which was later traced to a Russian IP address, failed, said the
IT manager, who spoke on condition of anonymity. In September 2007, MessageLabs
detected 1,100 suspicious e-mails to senior executives at companies around the
world. The messages, ostensibly from a recruiter, used a Microsoft error message
to lure victims into clicking on a Rich Text Format attachment. That enclosure
contained an executable file that would install two files on the target computer
then pass information back to the perpetrator.

Advertisment

F-Secure Corp, a security firm in Helsinki, Finland, has followed similar
threats for two years. “It's obvious in these cases that the attackers have
taken effort and time finding and researching the target,” said Mikko Hyppönen,
Chief Research Officer, F-Secure.

Software and social networking

In designing such messages and selecting recipients, criminals use not only
relatively sophisticated software tools, but also the reams of publicly
available information about corporate executives. That data comes from US
Secu­rities and Exchange Commission docu­ments and corporate websites, and also
from social networking sites like LinkedIn, Zoom and Facebook, where
infor­mation that executives post can be seen by anyone.

Details about past jobs, college affiliations and major projects can all be
used to create messages that the recipients are likely to open.

Advertisment

In such cases, an attached Word or Excel file is likely to carry a Trojan
horse. “It really is a document,” Hyppönen explained, “but it's corrupted, and
it will crash your version of Word and run the exploit.”

F-Secure has seen cases where hackers were able to identify the anti-virus
program the target company was running and modify the exploit code just enough
to go undetected.

Inside jobs

The prospect of executives becoming targets is particularly troubling
because the perpetrators often deploy sophisticated Trojan horses, and the
attacks require a disturbing amount of inside corporate knowledge to work
successfully. That knowledge sometimes comes from inside sources who know what
data the targeted executive is privy to and which employees he might be inclined
to trust.

F-Secure has seen 20 to

25 such attacks in two years, Hyppönen estimated. “It's not awfully common,
but in those cases where it happens, it's a real nightmare,” he said. Sometimes
the breach “was discovered when the sysadmins looked at firewall logs and at
where users were connecting and looked for anomalies,” Hyppönen explained. An IT
manager might see that those two workstations in the R&D department are
connecting to a server in China where they shouldn't be connecting.

Advertisment

In other cases, since the exploit sometimes uses software rootkits, a user
might start having PC problems. When IT then runs F-Secure's BlackLight or
another rootkit detector for debugging and finds a problem, it can detect the
presence of malware. An unforeseen consequence of the social networking trend is
that it plays into the hands of C-level attackers.

George Brown, a database and security consultant, said he tells CEOs to guard
their private information zealously. “It's the Wild, Wild West out there.
Publicly held companies are forced to reveal a lot of information about their
executives, so that's already out there. I tell them not to compound that by
putting more information up on social networking sites,” said Brown, CEO,
Database Solutions Inc, NJ. “Don't put anything out there that you don't
absolutely have to.”

How to fight back

As a solution provider your job is to make top execs understand the threat
and show them how to mitigate it. Here are some steps to take:

Advertisment
  • Bolster security for executives, both in the office and at home.
  • Make sure anti-malware software and services are up to date at the desktop,
    server and network levels.
  • Strictly enforce basic security practices, including frequent changes of
    passwords.
  • Immediately plug any security holes in Word, Excel or Acrobat.
  • Ensure that the operating systems on handheld devices-typically beyond the
    scope of desktop antivirus programs-are always up to date.
  • Drill executives on whom to notify if they click on a Word, Excel or PDF
    document received via e-mail and the application appears to launch but then
    shuts down and relaunches. This may indicate that a Trojan horse is attempting
    to cloak itself behind the real application.
  • Teach them to be wary when an e-mailed document requests that they run
    resident macros. Rule of thumb: If there is any doubt about the validity of the
    request, don't do it.
  • Insist that executives who travel always use a virtual private network when
    linking into company networks from outside.
  • Forbid them to send confidential information of any kind-including personal
    information-over an unsecured Wi-Fi connection.
  • Be wary of social networking.
  • Explain that criminals may be watching high-profile posters with something
    other than benign interest.
  • Make them aware of social engineering tactics that could prompt them to
    unwittingly give away their bank account numbers or put the company at risk.
A Near Miss Of
C-Level Attack

Last summer,
24-year-old Russian Igor Klopov and four others were indicted by a New York
grand jury for stealing $1.5 million and attempting to steal $10.7 million
more from about a dozen victims. Klopov used the Forbes 400 list of the
world's wealthiest people to pick his marks. They included Texas businessman
Charles Wyly and TransUnion Credit President Anthony Pritzker.

The government charged that Klopov and his
gang found information on some of their victims' real estate holdings and
lines of credit-much of which was publicly available-and used it to build
dossiers on them. The gang allegedly created and used fake IDs to contact
the victims' financial institutions (JPMorgan Chase, Merrill Lynch and
Fidelity Investments) to try to gain information on their accounts, get
duplicate checkbooks and the like. Luckily, the institutions flagged the
attempts and c
ontacted the authorities.

Courtesy: F-Secure Corporation