Newsletter:

Skip Navigation LinksHome > News > Security > Spammers exploit email meeting invitations

Spammers exploit email meeting invitations

28 March 2008 06:49AM
Tags: spammers | exploit | email | meeting | invitations

Spammers are using email meeting invitations to circumvent spam filters, security experts have warned..

Trend Micro has tracked spam in numerous formats over the past 12 months, but this is the first time that the Google Calendar system has been used as a mechanism.

Most spam filters are designed automatically to weed out attachment or image spam, but are less likely to be set up to track this new delivery mechanism.

Unlike standard email, meeting invitations contain specialised information in the header allowing them automatically to update and cross-reference the calendaring system.

Extra information such as links and attachments can be added to the invitation, giving the spammers a way to deliver their payload.

Trend Micro said that the email invitations are personalised with a different link sent to each recipient, and may be configured to send meeting alerts in order to draw increased attention to the spam message.

"We will most likely see this delivery method used for other types of spam, such as pump-and-dump, links to web threats, etc," said Jamz Yaneza, research project manager at Trend Micro.

"It is likely that, on the back of this first attack, we can expect to see tools like Google Calendar further abused to contain malicious links and to steal sensitive information."

Trend Micro is warning all businesses and end users to demonstrate extra caution when receiving unexpected meeting invitations and other unexpected mail.

Copyright © 2008 vnunet.com

   


Ads by Google


Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 


Tripwire - Click here to win an iTouch





Product Reviews

Star Rating
The Cyber-Ark Enterprise Password Vault, or EPV, is a high-end password management powerhouse.
Star Rating
The Hitachi ID-Archive sets its focus on password randomisation.
Star Rating
The Lieberman Software Enterprise Random Pass­word Manager is a full-on password manager and randomiser for...
Star Rating
Proginet SecurForce is a little bit of a horse of a different color for this month's Group Test.
Star Rating
On the surface, RoboForm Enterprise starts out looking like a single sign-on product, but that is just on the...
Unified Communications Podcast Centre

TopTopics
(7040) -  microsoft
(6493) -  iinet
(6484) -  copyright
(6484) -  afact
(6423) -  internet
(5934) -  servers
(5934) -  mipi
(4295) -  telstra
(4106) -  phone
(3745) -  broadband
(3672) -  nvidia
(3587) -  nbn
(2439) -  avg
(1972) -  onecare
(1924) -  google