Friday

Security.nl, Maarten, social engineering and targeted attacks



Security.nl did a 2-part article interviewing Maarten van Hoorenbeeck. It's in Dutch but you could try Babelfish or Google Translate. Maarten is an expert in targeted attacks and I have enjoyed his various blog articles on the subject. Not forgetting his excellent presentation on 24C3: Crouching Powerpoint, Hidden Trojan. He mentions a lot of points that we discussed before:

  • social engineering has become an important part of attacks
  • myspace, linkedin etc.... are providing social engineering material
  • targeted attacks are definitely on the rise
  • executive management is becoming a favorite target (spearphising)
  • 0-day exploits are being used, especially in office documents (doc, ppt, xls etc)
  • Antivirus detection in these cases is very poor
Reading the two articles is highly recommended:
  1. Hyves helpt hackers bij gerichte aanvallen (security.nl)
  2. Als dodelijke PDF's je netwerk infiltreren (security.nl)
BONUS: Spearphishing is back (SANS ISC)

0 comments: