06/17/2016
Sharing this with everyone; it affects mostly Lawyers and Law offices, but thought it was important enough to post on our page. Reprinted with permission.
NEW YORK STATE CYBER COMMAND CENTER THREAT ALERT
DATE: June 16, 2016
SUBJECT: Malicious Email Campaign Targeting Attorneys - Spoof Emails From Statewide Legal Organizations - TLP: WHITE
OVERVIEW:
In June 2016 a trusted third party became aware of a malicious email campaign targeting attorneys, which spoofs emails from statewide legal organizations, such as the Bar Association and the Board of Bar Examiners. The subject and body of the emails include claims that “a complaint was filed against your law practice” or that “records indicate your membership dues are past due.” Recipients are asked to respond to the claims by clicking a link which leads to a malicious download, potentially ransomware.
The emails are well written and appear to originate from an appropriate authority, such as an Association official, likely increasing the effectiveness of the email. Reporting from various states indicates a likelihood that this campaign is personalized to individuals practicing in a particular state and may be progressing on a state-by-state basis. The following states have been referenced in public reporting on this campaign: Alabama, California, Florida, Georgia, and Nevada. This targeting may include attorneys working for state, local, tribal, and territorial (SLTT) governments.
RECOMMENDATIONS:
· Share this information with potentially impacted organizations including Departments of Law/Justice, related law enforcement agencies, and agency-specific offices of counsel.
· Look for spear phishing emails which may include spoofed email addresses, unusual requests, and questionable and/or masked links. This particular series of emails includes what appears to be a link to the state bar association, but when the user hovers over the link it shows that the link is really to a different website. Copying and pasting the link, instead of clicking on it, would defeat this social engineering attempt.
· Perform regular backups of all systems to limit the impact of data loss from ransomware infections. Backups should be stored offline.
· Report any suspicious emails to the Cyber Command Center at [email protected]
The Cyber Command Center will update this alert as new information is obtained. If there are any questions, please contact the Cyber Command Center at 518-242-5045 or [email protected]
NYS Cyber Command Center
NYS Enterprise Information Security Office
Office of Information Technology Services (ITS)
1220 Washington Avenue, Building 5 – 1st Floor
Albany, New York 12226
Main Phone: 518-242-5045 | [email protected]
Website: http://www.its.ny.gov/eiso