Trustwave SpiderLabs Uncovers Critical Cybersecurity Vulnerabilities Exposing Manufacturers to Costly Attacks. Learn More

Trustwave SpiderLabs Uncovers Critical Cybersecurity Vulnerabilities Exposing Manufacturers to Costly Attacks. Learn More

Managed Detection & Response

Eradicate cyberthreats with world-class intel and expertise

Managed Security Services

Expand your team’s capabilities and strengthen your security posture

Consulting & Professional Services

Tap into our global team of tenured cybersecurity specialists

Penetration Testing

Subscription- or project-based testing, delivered by global experts

Database Security

Get ahead of database risk, protect data and exceed compliance requirements

Email Security & Management

Catch email threats others miss with layered security & maximum control

Co-Managed SOC (SIEM)

Eliminate alert fatigue, focus your SecOps team, stop threats fast, and reduce cyber risk

Microsoft Exchange Server Attacks
Stay protected against emerging threats
Rapidly Secure New Environments
Security for rapid response situations
Securing the Cloud
Safely navigate and stay protected
Securing the IoT Landscape
Test, monitor and secure network objects
Why Trustwave
The Trustwave Approach
Awards and Accolades
Trustwave SpiderLabs Team
Trustwave Fusion Platform
SpiderLabs Fusion Center
Security Operations Centers
Technology Alliance Partners
Key alliances who align and support our ecosystem of security offerings
Trustwave PartnerOne Program
Join forces with Trustwave to protect against the most advance cybersecurity threats
SpiderLabs Blog

Malware Authors Adopt CEO Fraud Techniques

CEO Fraud scams, a type of Business Email Compromise (BEC), have gained popularity among scammers recently. These scams use the power of the CEO's name to try and elicit a response from a targeted employee of an organization. For more information on the issue of CEO Fraud, and counter-measures, see our other blog here. The reported incidents and financial losses to date prove that the CEO Fraud email attack technique is effective in penetrating company defenses. SpiderLabs is keeping a close eye on such attacks for any variation or shift in the techniques.

Last week we came across an eye catching sample. At a glance it looked definitely like a CEO Fraud as it manifested all the behaviors of the recent CEO Fraud emails the team have been dealing with – like the word "payment" in the "Subject", the person in the "From" field was already used in an earlier similar attack and text in the body suggesting it came from a mobile device. What really us curious about the sample was the addition of the attachments as shown in Figure 1. Not just one but two attachments, a PDF and a GZIP. It was odd that this CEO Fraud email contained attachments. Another point of interest was the text in the email body suggesting that the recipient really needs to open the attachments. This is not a new trick – lot of malicious email use this sort of social engineering technique to trick users into opening attachments.


Figure 1. CEO Fraud email with attachment.

Just to be sure, we searched the email header as shown in Figure 2, and, as suspected, a certified CEO Fraud. A CEO's name and a non-related Gmail email address in the "From" field and addressed to an individual in the finance department of the company, which was verified by simple googling.


Figure 2. Email Header.

The PDF attachment was interesting. Would it be a real invoice ? Or would it be some sort of PDF malware? What was certain was that it was a CEO scam based on the email structure and content.

The next step was to extract the attachments and view them. The PDF file was the first to be analyzed by conducting a visual analysis with the help of analysis tools. An initial search of suspicious strings was made on the PDF file and the "URI" string was found as shown in Figure 3. Other suspicious strings usually found in malicious PDF files were not present in the file.


Figure 3. URI found inside the PDF attachment.

After the visual search, we then opened the PDF file in a controlled environment and observed its behavior. When opened, the image in Figure 4 showed up which further increased our suspicion about this PDF.


Figure 4. The PDF when viewed in a PDF reader.

This is an image with the underlying URI link found earlier during the visual search. The image in the PDF, when clicked, redirects the user to the website as shown in Figure 5.


Figure 5. Page view of URL.

The page, images and all, were crafted carefully. Any unsuspecting user might interpret the page as a real Adobe PDF Online page, but not security researchers. Notice the hyperlinked "Download" string which, when clicked, will initiate downloading a zip file from the following link:


The "View Document" button performs the same action as downloading from the first link. At this point we were certain that the zip file was malicious because an executable named "Order-Details.exe" was inside the zip file, but with a PDF icon. It's an old trick of making out the file to be a legitimate PDF if the showing of extension names is disabled in the operating system environment.

From the point when the PDF file was opened to the point the zip file was downloaded, we violated a bunch of security protocols. But security researcher are curious! (Readers, do not attempt to do the same, always be cautious about everything that you try to open unless you are a security enthusiast).

A quick analysis on the executable file was conducted and found out that it was a password-stealing Trojan. The collected information is sent to remote servers controlled by the attacker. So in summary, the attack is a PDF that provides a link to self-download an executable file into your system.

The investigation continued and the second attachment "payment-info@#002.gz was extracted out from the email. Again, it contained another executable file named "PO DETAILS 2.exe". It has a different icon this time. Another quick analysis was conducted on the file and this showed it was a variant of Fareit, another password-stealing Trojan that steals login credentials for known FTP applications and sends the collected information to a remote server.


Malware authors appear to have noticed the success of CEO fraud's social engineering techniques in penetrating security defenses and they are now using these techniques to gain access to the internal network of the targeted organization. CEO fraud has thus gone up a level from financial scams to malware distribution, and, as such, poses an even greater threat to the security of any organization.

We anticipate there will be more varieties of malware that will be distributed using these CEO fraud email techniques in the future.

Latest SpiderLabs Blogs

Trustwave SpiderLabs Report: LockBit 3.0 Ransomware Vs. the Manufacturing Sector

As the manufacturing sector continues its digital transformation, Operational Technology (OT), Industrial Control Systems (ICS), and Supervisory Control and Data Acquisition (SCADA) are becoming...

Read More

Overview of the Cyberwarfare used in Israel – Hamas War

On October 7, 2023, the Palestinian organization Hamas launched the biggest attack on Israel in years, resulting in numerous casualties and hostages taken. Israel responded with a large-scale ground...

Read More

The 2023 Retail Services Sector Threat Landscape: A Trustwave Threat Intelligence Briefing

The annual holiday shopping season is poised for a surge in spending, a fact well-known to retailers, consumers, and cybercriminals alike. The latter group, however, is poised to exploit any...

Read More