• Log In
  • Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • HomePage
  • Instructor
  • Syllabus
  • Schedule
    • First Half of the Semester
      • Week 1: Course Introduction
      • Week 2: Meterpreter, Avoiding Detection, Client Side Attacks, and Auxiliary Modules
      • Week 3: Social Engineering Toolkit, SQL Injection, Karmetasploit, Building Modules in Metasploit, and Creating Exploits
      • Week 4: Porting Exploits, Scripting, and Simulating Penetration Testing
      • Week 5: Independent Study – Perform Metasploit Attack and Create Presentation
      • Week 6: Ettercap
      • Week 7: Introduction to OWASP’s WebGoat application
    • Second Half of the Semester
      • Week 8: Independent Study
      • Week 9: Introduction to Wireless Security
      • Week 10: Wireless Recon, WEP, and WPA2
      • Week 11: WPA2 Enterprise, Wireless beyond WiFi
      • Week 12: Jack the Ripper, Cain and Able, Delivery of Sample Operating Systems
      • Week 13: Independent Study – Analyze provided Operating System Samples and Create Assessment Report
      • Week 14: Deliver Assessment to Operating System Class either in person or via teleconferenc
  • Assignments
    • Analysis Reports
    • Group Project Report and Presentation
  • Webex
  • Harvard Coursepack
  • Gradebook

MIS 5212-Advanced Penetration Testing

MIS 5212 - Section 001 - Wade Mackey

Fox School of Business

Hackers who took control of PC microphones siphon >600 GB from 70 targets

February 22, 2017 by Jason A Lindsley 1 Comment

Hackers compromised PC microphones using malware embedded in Microsoft Word documents.  The attack targeted companies in several industries, including critical infrastructure, news media, and scientific research.  The data was siphoned via Dropbox accounts.

The article states that organizations typically don’t prevent end users from accessing Dropbox.  In this day in age, that needs to change.  DLP strategies for companies in each of these industries should be blocking these cloud sharing sites.  Any exceptions to these blocks should be closely monitored.

On another note, I would hate to be the one that had to listen to hours of audio to try to find the sensitive information, intellectual property, trade secrets, and research data!

 

https://arstechnica.com/security/2017/02/hackers-who-took-control-of-pc-microphones-siphon-600-gb-from-70-targets/

Filed Under: Week 06 Tagged With:

Reader Interactions

Comments

  1. Scott Radaszkiewicz says

    February 23, 2017 at 12:50 pm

    Good article Jason. Over the past several years here at my organization, we have pushed users to use cloud storage vs. local storage. I work in a K-12 school district. In fact, our High School and Middle School Students have devices issued to them and they use Google Drive for all of their storage. We even tell students to create a dropbox for extra storage, if needed. It just goes to prove that hackers will continue to target things that people use and feel comfortable with. It’s a never ending battle!

    Log in to Reply

Leave a Reply Cancel reply

You must be logged in to post a comment.

Primary Sidebar

Weekly Discussions

  • Uncategorized (35)
  • Week 01 (2)
  • Week 02 (14)
  • Week 03 (13)
  • Week 04 (10)
  • Week 05 (7)
  • Week 06 (29)
  • Week 07 (8)
  • Week 08 (1)
  • Week 09 (6)
  • Week 10 (12)
  • Week 11 (7)
  • Week 12 (4)
  • Week 13 (6)
  • Week 14 (18)

Copyright © 2025 · Magazine Pro Theme on Genesis Framework · WordPress · Log in