Security Management
Published on Security Management (http://www.securitymanagement.com)
Phishing E-mails Spoof Payroll Services
By John Wagley
Created 08/09/2012 - 15:03



    
Wrap-Up?: 
No
Weight: 
0
Lead Headline?: 
Yes
Date: 
08/09/2012
By Line: 
By John Wagley
Teaser: 

In recent weeks, fraudulent e-mails purporting to be from payroll companies have aimed to lure recipients into downloading data-stealing malware onto their computers.

In recent weeks, fraudulent e-mails purporting to be from payroll companies including Automated Data Processing (ADP) have aimed to lure recipients into downloading malware onto their computers.

Message subject lines have included “ADP Generated Message: First Notice--Digital Certificate Expiration” and “ADP Security Management Update,” according to a recent ADP security alert. [1]

The e-mails contain a link directing users to sites that deliver exploits, including one that targets a Java Runtime Environment (JRE) vulnerability, according to a recent blog post [2]by SANS Institute incident handler Daniel Wesemann. The messages aim to steal sensitive payroll, financial, and human resources information, he notes.

The attacks appear to be able to evade many antimalware programs, according to Wesemann. One main defense is to update JRE software, he states. He also suggests reminding human resources and payroll employees to avoid clicking on suspicious e-mail links. Such employees “are your first line of defense, and--given antivirus’ ineffectiveness--usually even your only line of defense.”


♦ Photo by Flickr/Dastryh1 [3]

Related Resources: 
Thumbnail: 

Comments


Security Management is the award-winning publication of ASIS International, the preeminent international
organization for security professionals, with more than 38,000 members worldwide.

ASIS International, Inc. Worldwide Headquarters, 1625 Prince Street, Alexandria, Virginia 22314-2818 U.S.A.
703.519.6200 | fax 703.519.6299 | www.asisonline.org

ASIS

© 2013 Security Management
This site is protected by copyright and trade mark laws under U.S. and International law.
No part of this work may be reproduced without the written permission of Security Management.

Powered by: Phase2 Technology

Source URL: http://www.securitymanagement.com/news/phishing-e-mails-spoof-payroll-services-0010205

Links:
[1] http://www.adp.com/about-us/trust-center/security-alerts.aspx
[2] http://isc.sans.edu/diary.html?storyid=13840
[3] http://www.flickr.com/photos/daphnestuij/4873426510/sizes/m/in/photostream/