Symantec says it’s found a spear phishing attack aimed at financial, governmental and economic development organizations that is delivered via attachments that purport to come from a G20 summit representative.
The Group of Twenty Finance Ministers and Central Bank Governors is set to meet in St. Petersburg, Russia for a 2 day summit starting Sept. 5. Phishers are using the same remote access trojan used in a hacking campaign targeted against chemical and advanced material companies dubbed “Nitro” by Symantec in 2011, says Symantec security research Satnam Narang in a Sept. 3 blog post.
The email carries a compressed folder containing five files, two of which are masquerading as different file types, Narang says. One has a .msg file, which when opened will run an executable contained in the compressed folder and open up a Microsoft Word document with the heading “Growth Through Quality Jobs” that even has track changes featuring comments from the “UK Government.”
In the document, the “UK Government” notes that their “suggested language strike a more positive note and reflect language by Employment and Finance Minister.”
Narang says Symantec can’t verify the authenticity of the documents as genuine G20 documents or not.
CSO Online notes that August has seen a spike in the level of phishing attacks using the G20 summit as bait. One of the groups involved, it says, is the same Chinese team responsible for hacking into the New York Times. The group is known as Calc Team and may have ties to the Chinese military.
For more:
– read the Symantec blog post
Related Articles:
Slight shift seen in official Chinese attitude on cybersecurity
‘Nitro’ hackers target chemical and defense companies, says Symantec
ENISA: Cybersecurity concerns will cause email abandonment
