The Next Rotation - The Universe of Fenris Fox
20 January 2007
 
Shadows of Cyberspace: "Dynamite Phishing:" Is it spyware or phishing? You be the judge.

One of my folks got an email today purporting to be a notification about Windows file errors. Now, he didn't follow any links in it - since I taught him to watch out for that sort of thing - but I ran into a small dilemma while examining it.

The email linked to a randomly-generated subdomain on a domain close to sick-online-games.orgy (for obvious ethical reasons, I won't put a working link to a possibly dangerous domain here).

I'm pretty sure that this email used a technique which I don't have a proper name for - deceiving users into downloading a program that claims to do something beneficial, but likely does something malicious.

While "Trojan horse" might apply to this program, it seems to be a poor fit. When I think of a Trojan horse, I think of something at least somewhat targeted; this thing seems to be spewed out at random. What it really is, is a combination of spyware and phishing.

Expounding on the analogy of "spear phishing" - which is a phishing email specially crafted and targeted to a single person or company - I propose the term "dynamite phishing."

In real life, some (unscrupulous) fishermen have used dynamite (or other suitable explosives) to stun or kill large numbers of fish, which then float to the surface.

Similarly, a computer program (malware) distributed through a phishing email would have much more potential impact - power - than simply scamming the user out of a single set of information. That malware could continue to spy on the user and steal information indefinitely; it's the "dynamite" in dynamite phishing.
 
Comments: Post a Comment

Links to this post:

Create a Link



<< Home
Assorted writings & artwork of a furry. Sometimes presented from the point-of-view of the author's "fursona" (personal furry): Fenris "Fenny" Fox, the futuristic kitsune.

+~~~LIVE FREE or DIE!~~~+

Schneier's Three Natural Laws of the Digital World

Name:
Location: Nevada, United States
ARCHIVES
July 2006 / August 2006 / September 2006 / October 2006 / November 2006 / December 2006 / January 2007 / February 2007 / March 2007 /


Photobucket - Video and Image Hosting
Syndicate me! +~~=:o)

Email the Blogmaster:
fenrisblog *removeme*@*removeme* gmail.com

(Munged to fool email address harvesting spam robot programs.)


Powered by Blogger

Creative Commons License
All works on this blog are licensed under a Creative Commons Attribution 3.0 United States License, unless otherwise noted (i.e., on a per-work or per-post basis).

NOTE: All works that were specifically noted as using the Creative Commons Attribution-ShareAlike 2.5 License, created prior to March 9, 2007, are hereby placed under this site's general license - an even less restrictive one.