26 Aug 2011
Security researchers at F-Secure have unearthed what they think is the email used to hack RSA in March.
The initial aim of the attack is believed to have been the theft of military secrets from Lockheed Martin and Northrop Grumman. It compromised RSA's SecurID token system, forcing the company to offer more than 20,000 business customers new SecurID tokens.
But rather than use a sophisticated new technology, the attack used a familiar social engineering trick. An email, spoofed to look like it had come from recruiting web site Beyond.com, was sent to an employee of RSA's parent company EMC.
The email, found by F-Secure's Timo Hirvonen, was titled '2011 Recruitment plan' and contained one line of content: 'I forward this file to you for review. Please open and view it'. Attached was an Excel spreadsheet.
On opening the attachment, a Flash object was executed by Excel that used the CVE-2011-0609 vulnerability to execute code and drop a backdoor known as Poison Ivy, before closing down Excel.
Poison Ivy then connected back to the attack server, allowing the hacker full remote access to the infected workstation and any network drives.
"The message was sent to one EMC employee and cc'd to three others," said F-Secure chief research officer Mikko Hyppönen in his blog.
"If there's any lesson to be learned it's that the human element is the greatest risk," Graham Cluley, senior technology consultant at security firm Sophos told Computing. "Technology can reduce the risks, but ultimately anyone making a bad decision can be the weak chink in your amour that exposes your internal systems."
Have your say on this article
Newsletters
Latest stories from Threats and Risks
You may also like
Threats and Risks jobs
Technology Patent Wars
Case studies from large organisations across all sectors
... And rich media, and flexible working, and peaks in traffic ...
Upcoming Events
Join us for this Computing web seminar, in which the Head of BI at the Co-operative Group Nick Colebourn will be explaining just how he reigned in the Group’s sprawling database estate and how significant savings were realised and data quality improved as a result.
Date: 31 May 2012
Time: 11:00 AM
Live June 13th 11:00am: Register now. During this web seminar we will be looking at the sorts of incidents that can bring data centres grinding to a halt and what can be done about them.
Date: 13 Jun 2012
Time: 11:00 am
Receive the latest jobs direct to your inbox
Are you being paid what you are worth?