We've seen a lot of spam campaigns recently that leverage the latest Boston Marathon bombings, but Trend Micro experts have identified one targeted attack that's worth mentioning.
It all starts with an email that comes in and is titled “Please pray for Boston.”
“Please pray for Boston”
The email goes something like this: “Two powerful bombs exploded near the finish line of the Boston Marathon on Monday afternoon, killing at least three people, including a child, and injuring at least 100. One of the city’s most beloved spring ceremonies was transformed from a scene of cheer and triumph into a bloody massacre and death.”
Attached to these messages is a seemingly harmless Word document. However, when someone opens the document, it will also run an executable file that is detected by Trend Micro as Troj_Naikon.A.
Troj_Naikon.A is designed to connect to the command and control server using SSL. The digital certificate used in the attack is filled with false information, such as “abc” for the organization name.
Using SSL ensures that the traffic sent between the malware and the server is encrypted, reducing the chances of it being detected by security software.
The server used for the malware's command and control center was previously used by another malware, which was active in 2011. However, given that so much time has passed since then, experts say it is unclear whether there is a connection between the two.
“Using SSL encryption to communicate with the C&C server has its advantages, particularly in avoiding detection by security software,” says Trend Micro Nart Villeneuve Senior Threat Researcher .
“However, we can take some preventative measures, such as looking for random or empty SSL values in certificate fields by default and limiting scans to certificates provided by external networks.”
