Spammers Use Excel to Cloak Malware

Spammers are using Microsoft Excel as the newestof 2007. The report showed PDF-spam made up
packaging for their spam, says Commtouch, a10-15% of global spam messages during a 24-hour
Nasdaq-listed anti-spam technology provider. Theperiod, increasing overall global spam traffic by
finding is based on the company's analysis of billions30-40%.
of email messages globally.Image spam dropped 50% to less than 15% of all
"Like other types of spam messages, the Excel spamspam in that period. In the previous quarter of the
is being sent from zombie computers or bots typicallyyear, image spam accounted for 30% of all spam in
home PCs that have previously been infected bythe first quarter of 2007. The report also showed
Trojan malware," the company says in a mediaglobal spam levels remained high, with 85-90% of all
statement.global email being spam.
The Excel spam packaging promotes stocks in fileLev says spammers assume that by wrapping the
attachments with names like "invoice20202.xls,"same message in a new format, they will bypass
"stock information-3572.xls," and "requestedmost anti-spam engines that try to analyze the
report.xls."content of mail messages.
Commtouch CIO Amir Lev says Excel is a naturalHowever technologies that rely on identifying
progression after a recent spate of PDF spam, whichpatterns in mass emails block these types of
itself was a development from basic image spam.messages automatically, regardless of the content or
"We expect other file formats to follow suit; think offormat.
the spam potential in PowerPoint files, or WordMalware writers have used Excel in the past as a
documents," he says.carrier for viruses. In June and July 2006, a series of
Other file formats Commtouch recently released itsattacks exploited vulnerabilities in Microsoft software,
Email Threats Trend Report for the second quarterincluding Excel, Microsoft Word, and PowerPoint.