Targeted Trojans are usually aimed at specific individuals within an organization with the purpose of infiltrating networks for corporate espionage. Each attack is usually small in numbers and often utilizes social engineering techniques, such as personalization, to persuade the recipient to open the email and attachment.
Hackers are constantly shifting to new delivery formats to hide the sinister malware and to avoid detection by traditional anti-virus engines, as well as using harmless and common attachment types which are not blocked. In these instances, Microsoft Office Database (MDB) files, usually hidden within a ZIP file, is one of the latest formats to be used. Once the MDB file has been downloaded the MDB exploit will drop an EXE file to the disk and steal data. MessageLabs predicts that in the coming year hackers will vary their use of formats even further with 1 Byte XOR Key, Multiple XOR keys and ROR, ROL, ADD and SUB formats to be exploited.
Alex Shipp, MessageLabs Senior Anti Virus Technologist and Imagineer, issues an ominous warning to businesses, “These attacks are highly targeted at organizations that have highly confidential and valuable data, such as military and government bodies. Presuming that you haven’t been targeted isn’t proof that you haven’t. The malicious EXE file can remain undetected for several months so it may be that your organization has been penetrated and crucial information has already leaked. Businesses need to up their game and fortify themselves against a dangerous new breed of hacker, Hacker 3.0, who is prepared to stop at nothing to achieve their goal.”