
If you believe that technology could be bridging the generation gap, think again. According to Deloitte’s first State of the Media report it’s as stark as ever.
read more
Lia Timson
Thursday, 12 June 2008 08:31
The previously unseen plot was uncovered by web security company MessageLabs during a routine outbound mail filtering process.
The would-be hacker used a genuine vacancy advertisement on an unnamed large Australian recruitment agency’s site to apply for the job by filling in the mandatory online application form and attaching a covering letter.
The letter was produced in rich text format (RTF) and contained an embedded PDF file of, supposedly, the applicant’s resume. Instead it contained a malicious executable program designed to open the recipient’s systems to back-door trojan attacks.
As it is common with such online application forms, the recruitment agency’s system automatically generated an email and attempted to forward the attachments to the vulnerable employer.
Philip Routley, spokesman for MessageLabs, says it is the first time such tailored attempt has been identified.
“It looks like a genuine letter and has an embedded file that looks like a genuine CV in PDF. It’s a well-crafted application that wouldn’t really raise any alarm bells with a human resources person,” Routley says.
“By double-clicking on the PDF, nothing happens on the screen, but in the background the malicious file embeds itself on the PC and opens the pipe for hackers to potentially steal corporate information.”
Recent recruitment-based malware attempts were linked to unsolicited job applications sent to targeted company’s senior managers and board members. In this case, their details were harnessed from company websites and from hackers disguised as members of business networking sites (Continues on page 2).

(Continues on page 2).
Think again. Most businesses only have PART of a DR plan - and this spells business disaster in the event of an IT disaster.
Download The Seven Sins of Disaster Recovery White Paper now and find out how you can prevent this happening to you.