Trend Micro said Friday that in addition to the spear phishing attempts on Google’s Gmail, the company has traced efforts to penetrate Yahoo Mail and Microsoft’s Hotmail as well.
Trend Micro said that the attacks on the other two email systems were apparently “separately conducted,” but the objectives were the same: obtain the logins and passwords of the user, as a foundation for staging future attacks.
On Wednesday, Google disclosed that hundreds of its Gmail accounts had been compromised, including personal email accounts used by reporters, activists, and government officials. The attacks appeared to have come from servers in China, Google said, although Chinese officials denied responsibility. Secretary of State Hillary Rodham Clinton called the attacks “very serious”, and said the FBI had begun an investigation. The White House said Friday that no government email accounts were compromised in the attacks.
Phishing uses social engineering to try and persuade the victim to divulge personal details, including their username and password.
“The objective of the attackers appears to be to gain access to the target’s Webmail accounts in order to monitor his/her communications and, possibly, to stage future attacks,” Nart Villeneuve, a senior threat researcher for TrendLabs, said in a blog post. “In the recent case revealed by Google, the attackers used a phishing attack to gain access to the target’s Gmail account then proceeded to add their own email addresses to the “forwarding and delegation settings,” allowing them to send and receive email messages via the compromised accounts.”
via Report: Gmail Attacks Replicated on Hotmail, Yahoo | News & Opinion | PCMag.com.