IT DRILLDOWN
 
NEWSLETTERS
 

CIO.com updates, insights and advice on technology, management and your career.

 
 
 
LEADERSHIP
 
CIO Executive Programs
The Leader in Face-to-Face Education for Senior Executives

Offering regional and national programs, CIO (and CSO) events bring together some of the most respected names and thought leaders in information technology and security. Presented by CIOs and other senior level executives, these invitation-only programs offer timely topics and strong networking. Learn More »

 
CIO Executive Council
A Peer-Advisory Service and Professional Association for CIOs

Public Teleconferences
Join CIO Executive Council members and participate in the following live one-hour teleconferences:

* Transforming IT Teams
September 16

* Global CIOs: How to Lead on the World Stage
September 18

* Social Responsibility's Strategic Benefits
October 29

More / Register »

Learn more about the CIO Executive Council »



 
 
RESOURCE CENTER
 
 
 
SUBSCRIBE TO CIO
 
Are you involved in setting the direction for your company's IT budget or strategy?

Apply today for a FREE subscription to CIO Magazine!

 
 

Audio Spam: The Latest Twist on a Never-Ending Security Threat

Researchers say that small MP3 attachments pitching penny stocks are the latest wave in the ocean of unsolicited e-mail.

 

October 18, 2007CIO — A new form of spam using MP3 audio files to send a stock pitch has surged today. Today this audio form of spam has risen from being virtually nonexistant to become 10 percent of all spam traffic, according to several security researchers tracking the phenomenon.

The outbreak is the latest in a string of tactics from the past six months which avoid filters by using file formats not generally blocked or difficult for filters to disassemble and search. It started with "image spam" which used picture files to bypass filters. That was followed by spam that used the PDF file format. Now the audio MP3 version of the spam is spreading rapidly.

In each case, the primary use of the spam is for a pump-and-dump stock scheme. The message tries to entice its viewer (or listener) into investing in a penny stock. If enough recipients decide to invest, the price surges, sometimes doubling. The originators of the scheme then dump their shares at the peak price. The tactic was so effective with image spam that the SEC halted trading on many penny stocks to stop the problem.

In the audio version, the user receives an MP3 file that is socially engineered with a name that invites clicking—either because it is a popular band name or title that seems personal. Some documented titles include: dadsong.MP3, oursong.MP3, weddingsong.MP3, santana.MP3, sayyousayme.MP3, smashingpumpkins.MP3, bbrown.MP3, bspears.MP3, gloriaestefan.MP3, beatles.MP3; answeringmachine.MP3, coolringtone.MP3, listentothis.MP3 and elvis.MP3, according to researchers at Cyberoam, who are tracking the problem. The files range in size from 88KB to 150KB.

When opened, the user hears a synthesized voice pitching the penny stock. The quality is extremely poor. Here's a sample (126KB) from the labs at SecureWorks, which are also tracking the audio spam.

SecureWorks senior security researcher Joe Stewart says his first reaction was that audio spam, while clever, is probably destined for a lower success rate, both because of the poor quality of the audio and because of the amount of end user intervention required. "Who's going to open a stranger's MP3 and listen, and what's the chance they'll repeat that action?" says Stewart. "With visual spam, all you have to do is glance." What's more, in many inboxes the visual is displayed as the message is selected, making it hard to avoid seeing.

Loading...
 
 
CENTER OF EXCELLENCE
 
Security
» New 2008 Report: Outbound Email and Data Loss Prevention in Today's Enterprise
Email, blogging and mobile devices are important business tools, but they expose enterprises to legal, financial and regulatory risks.
» Regulations Shift Focus on Outbound Email Security
Outbound email is essential to running any business today — allowing us to share information, work with partners and even interact with customers.
» Messaging Security Goes Virtual
When it comes to technology investments, virtualization demonstrates drop-dead-obvious ROI.
» Encryption Made Easy: The Advantages of Identity Based Encryption
Growing regulations are pressuring enterprises to find effective, affordable and easy email encryption solutions.
» The Great Email Security Debate: Appliances, SaaS, or Virtual?
Today, there are many ways to approach email security — the question is: what deployment model is right for you?
Center sponsored by

 
 
ABCs
 

Just the basics, please. Sometimes we all need a refresher or we need to make sure our team and our colleagues are all on the same page.

Over 25 tutorials on everything from business intelligence to virtualization.

 
 
FEATURED SPONSORS
 
 
 
SPONSORED LINKS
 

File Integrity Monitoring: Secure Your Virtual & Physical IT Environments

Maximizing Site Visitor Trust Using Extended Validation SSL

How to Manage the Mobile Work Environment

Extending PCI Compliance to the Mobile Workforce

Building an Online Customer Experience Competency

Best Practices for Providing Secure and Cost-Effective Remote Access

How the Mac is Becoming an IT Standard in the Enterprise

Oracle Database 11g: Real Application Testing & Manageability

Reap the Benefits of Unified Communications

Efficient by design: Watch this flash demo of the Quad-Core AMD Opteron Processor

HP and Oracle deploy unbreakable computing infrastructure at Replacements, Ltd.

Optimizing Infrastructure Control

Effective Security with a Continuous Approach to ISO 27001 Compliance

How Does Your IT Help Desk Measure Up?

White Paper: Businesses Thrive by Unifying Business Communications

Getting Network Management Right: A Gartner IT briefing

Sheriff's Office Uses PocketCop to Access Police Databases from BlackBerry® Smartphones

The BlackBerry Solution Adds Significant Benefit to Toshiba

Write an RFP for Master Data Management: 10 Common Mistakes to Avoid

HP Puts Its Disaster-tolerant Capabilities to the Test

SOA Educational Library at the TIBCO SOA Resource Center

TDWI Report shows strong validation for investing in predictive analytics

Cost-Effective Data Center 1U Server Solutions

Secure your virtual and physical environments with the same software

GET YOUR VoIP ONTM! Win 2 Years of Hosted VoIP from Cypress. $100,000 retail value. Enter today!

Protecting Data in a Highly Networked World

Standalone Server vs. Open Source Toolkits

The Universal Wireless Client: Simplify mobility and reduce the cost of supporting mobile workers

Strategies for Asia-Pacific Expansion

They Can't Steal What You Don't Have: Smart Security Choices for Mobile Workers

Consolidation: Just the Starting Point for Virtualization

Storage Efficiency: The Key to Green Storage Operation

Getting Off on the Right Foot: Avoiding Common Master Data Management False Starts

The Challenge of Network Access Control -- Is a Managed Service the Answer?

Renowned Engineering Institution Chooses AMD Processor-Based Servers

New research validates telepresence solutions.

Configuration Assessment: Choosing the Right Solution

How to Calculate the ROI of Remote Support

31 Best Practices for the Service Desk

Unified Communications Software: The Death of VoIP?

Unify and Conquer: The Benefits of Unified Communications.

Heinz Uses a Wireless, Automated, Auditing process on BlackBerry® devices

Webcast: Solutions to the Toughest IT Challenges in Remote Offices

Network Immunity Manager Video

Dell Latitude: Battery life up to 19 hours. Learn more

Video: 21st Century Networking for a 12th Century Castle

Speed, agility, flexibility - The HP BladeSystem c-Class

Learn about the software-based VoIP solution from Microsoft

Microsoft System Center - Designed For Big

Accelerating ITIL at the Service Desk