Fake White House holiday e-mail is cyber attack

  • By LOLITA C. BALDOR The Associated Press
  • Wednesday, January 5, 2011 8:23pm
  • News

By LOLITA C. BALDOR

The Associated Press

WASHINGTON — A malware-laden e-mail masquerading as a White House Christmas card was a sinister move by hackers to steal sensitive documents from U.S. law enforcement and military officials, according to cybersecurity analysts.

The bright red and green holiday greeting, with the decorated Christmas tree, was sent out in late December and claimed to be from the “Executive Office of the President.” Cyber threat analysts said it was targeted at government officials, particularly those who are involved in computer crime investigations.

While it is not clear yet how many people got the malicious e-mail or how many documents were siphoned from their infected computers, analysts said there has so far been no evidence that any classified data was taken.

The targeted e-mail attack comes as the federal government is desperately trying to beef up its cybersecurity after the release of thousands of State Department cables and military documents by the WikiLeaks website.

Federal authorities want to improve technology systems and crack down on employees to prevent the theft or loss of classified and sensitive information.

A memo distributed this week by the White House Office of Management and Budget instructs federal agencies to complete assessments of system gaps and weaknesses as well as plans to upgrade networks and websites by Jan. 28.

The agencies must detail whether they have adequate procedures for workers accessing classified materials, how they determine who is given that access, and whether they use psychiatrists or sociologists to measure if employees are happy or grumpy and could pose a security threat.

The e-mail prompted recipients to click on a link, which would then download the ZueS malware — a well-known malicious code that is often used to steal passwords and other online credentials, primarily to poach Internet banking information. The malware was created several years ago and is widely available for criminals to acquire and adapt. It has been used to steal millions of dollars.

In this case, however, the code downloaded a second malware that is designed to steal documents from the recipient’s computer, accessing Microsoft Word and Excel files.

Don Jackson, director of threat intelligence for Atlanta-based SecureWorks, a computer security consulting company, said the attack was somewhat small and targeted to a limited number of groups with law enforcement, military and government affiliations.

It was small enough, he said, to suggest that is was sent out manually and not by a large network of infected computers. He said it was not large enough to be picked up by cybersecurity spam traps or sensors.

Alex Cox, principle research analyst for NetWitness, a cybersecurity firm in northern Virginia, said the email was sent out just a day or so before Christmas, delivered by a control server in Belarus.

He and Jackson said they believe this ZueS version was created by the same people who launched a similar but much larger attack last February.

Cox, who discovered the ZueS-infected malware last year when it infected at least 74,000 computers, said it’s hard to determine how many people were affected or how many documents were stolen in this latest attack.

Jackson said the hackers stole at least several gigabytes of data.

Analysts learned of the e-mail attack last week and have spoken with federal authorities about it.

Homeland Security Department spokeswoman Amy Kudwa said officials are aware of the ZueS e-mail and are monitoring it along with other similar malware attacks that have been tracked for some time.

Cox and Jackson would not disclose details on who was attacked or what documents may have been compromised but agreed that the hackers probably were after the documents, rather than any banking or financial passwords.

One theory, said Jackson, is that the hackers were looking for information about law enforcement cases and investigative techniques related to cybercrime so that they could sell it to other criminals.

The e-mail attack, however, underscores the continuing vulnerability of government workers and their computer systems to versions of the ZueS malware. Hackers can easily tweak the code each time so that it does not trigger antivirus software.

“Criminals have found that if they change the files in small ways it can slip past antivirus software,” said Jackson.

While ZueS-related attacks are fairly common, this latest one stood out because of the use of the White House connection to lure recipients in and the targeted way it went after law enforcement, analysts said.

One U.S. official said the code was rather poorly written. The hackers could only get easily accessible documents and not those filed deep within layers of folders on the hard drive, said the official, who spoke on condition of anonymity to discuss ongoing investigations.

More in News

Two dead after tree falls in Olympic National Forest

Two women died after a tree fell in Olympic National… Continue reading

Sue Long, left, Vicki Bennett and Frank Handler, all from Port Townsend, volunteer at the Martin Luther King Day of Service beach restoration on Monday at Fort Worden State Park. The activity took place on Knapp Circle near the Point Wilson Lighthouse. Sixty-four volunteers participated in the removal of non-native beach grasses. (Steve Mullensky/for Peninsula Daily News)
Work party

Sue Long, left, Vicki Bennett and Frank Handler, all from Port Townsend,… Continue reading

Portion of bridge to be replaced

Tribe: Wooden truss at railroad park deteriorating

Kingsya Omega, left, and Ben Wilson settle into a hand-holding exercise. (Aliko Weste)
Process undermines ‘Black brute’ narrative

Port Townsend company’s second film shot in Hawaii

Jefferson PUD to replace water main in Coyle

Jefferson PUD commissioners awarded a $1.3 million construction contract… Continue reading

Scott Mauk.
Chimacum superintendent receives national award

Chimacum School District Superintendent Scott Mauk has received the National… Continue reading

Hood Canal Coordinating Council meeting canceled

The annual meeting of the Hood Canal Coordinating Council, scheduled… Continue reading

Bruce Murray, left, and Ralph Parsons hang a cloth exhibition in the rotunda of the old Clallam County Courthouse on Friday in Port Angeles. The North Olympic History Center exhibit tells the story of the post office past and present across Clallam County. The display will be open until early February, when it will be relocated to the Sequim City Hall followed by stops on the West End. The project was made possible due to a grant from the Clallam County Heritage Advisory Board. (Dave Logan/for Peninsula Daily News)
Post office past and present

Bruce Murray, left, and Ralph Parsons hang a cloth exhibition in the… Continue reading

This agave grew from the size of a baseball in the 1990s to the height of Isobel Johnston’s roof in 2020. She saw it bloom in 2023. Following her death last year, Clallam County Fire District 3 commissioners, who purchased the property on Fifth Avenue in 2015, agreed to sell it to support the building of a new Carlsborg fire station. (Matthew Nash/Olympic Peninsula News Group file)
Fire district to sell property known for its Sequim agave plant

Sale proceeds may support new Carlsborg station project

As part of Olympic Theatre Arts’ energy renovation upgrade project, new lighting has been installed, including on the Elaine and Robert Caldwell Main Stage that allows for new and improved effects. (Olympic Theatre Arts)
Olympic Theatre Arts remodels its building

New roof, LED lights, HVAC throughout

Weekly flight operations scheduled

Field carrier landing practice operations will be conducted for aircraft… Continue reading