Login   |   Secure Purdue > News

ITaP Security and Policy Warns of Targeted Spear Phishing Attack

ITaP Security and Policy warns the Purdue community that the University has been specifically targeted by spear phishing attacks involving malicious PDF attachments. The attacker's attempt to trick users into opening an infected PDF in order to compromise a system. These compromised systems are then used as launching pads to perform further compromises of Purdue computer systems and network reconnaissance.

ITaP Security and Policy recommends that users do not open e-mail attachments that the user is not expecting. Potential malicious attachments may be titled:

  • Staff_Changes(purdue).zip, (or similar)
  • Any_Staff_Changes_About_Purdue_University.exe (or similar)
  • Leveraging_Ethernet_Card_Vulnerabilities_in_Field_Devices.pdf (or similar)

If you have received or opened any unusual or un-trusted attachments, named similar to the files listed above, contact ITaP Security and Policy immediately.

Report computer incidents to Purdue: http://www.purdue.edu/securePurdue/incidentReportForm.cfm

For questions concerning this advisory, please send email to: abuse@purdue.edu.

Posted by Curt Jansen on June 13, 2012, in Secure Purdue News.