Russian roulette
By John Leyden → More by this author
Published Thursday 13th September 2007 11:43 GMT
Webpages of the US Consulate General in St. Petersburg, Russia, were infected by malware earlier this week. The US consulate site was caught up in a much larger hack attack and is not thought to have been targeted as such.
The infected pages have since been cleaned up, reports net security firm Sophos which monitored results of the assault.
The attack on the US consulate was part of a larger campaign by cybercriminals targeting vulnerable web servers. The majority of the 400 compromised web pages hit by the attack were hosted in Russia. Hackers planted malicious scripts on compromised hosts.
After retrieving a copy of one of the infected Consulate pages from an internet cache, virus analysts as Sophos were able to identify the malware script planted on the site as Mal/ObfJS-C, a strain of web nasty that attempts to load further malware from a remote server. This malware includes a Trojan downloader script that attempts to plant backdoor code onto the PCs of surfers with vulnerable machines who visit infected sites.
The attack is described in much greater depth in Sophos's blog here. [...]
Read more ...
The Register. Security.
Showing posts with label Trojan. Show all posts
Showing posts with label Trojan. Show all posts
Friday, September 14, 2007
Friday, August 31, 2007
Pinch-bum malware creates titters
Cheeky Trojan drifts onto the net
By John Leyden
The general dumbing down of the virus creation process along with attempts by for-profit hackers to tie up the resources of security firms mean that anti-virus sofware vendors are beginning to need three alphabetical letters for some Trojan families.
Occasional this naming convention throws up a double entendre-loaded moniker, as when Trojan-Downloader-Small-Coc rose to prominence in May. This week security techies intercepted the first copies of Trojan-PSW-LdPinch-bum. How they laughed.
Summer, and the silly season that accompanies it, draws to a close on Saturday with the start of September
Read more ...
The Register
By John Leyden
The general dumbing down of the virus creation process along with attempts by for-profit hackers to tie up the resources of security firms mean that anti-virus sofware vendors are beginning to need three alphabetical letters for some Trojan families.
Occasional this naming convention throws up a double entendre-loaded moniker, as when Trojan-Downloader-Small-Coc rose to prominence in May. This week security techies intercepted the first copies of Trojan-PSW-LdPinch-bum. How they laughed.
Summer, and the silly season that accompanies it, draws to a close on Saturday with the start of September
Read more ...
The Register
Porn & Spyware Found on Govt. and School Sites
It would be great if the compromised Web servers I wrote about last week at Lawrence Livermore National Labs were an aberration, but sadly they are not. Conducting a simple Google search for adult-themed search terms found in ".gov" domains produces some very interesting results, including pages serving up adult videos along with a generous helping of spyware.
Several pages on both the official Web sites for the State of Louisiana and the Virgin Islands Housing Finance Authority show up prominently in the search results for porn at dot-gov domains. A handful of pages on those sites feature a blank video player that prompts the visitor to install a special video "codec" in order to view the adult movie.
Visitors who agree to install the codec inadvertantly agree to also install a piece of spyware that modifies your browser's home page, produces security alert icons on your Windows desktop, and serves nagging pop-up ads to install bogus anti-virus and anti-spyware security software.
Brian Krebs on Computer Security. The Washington Post Company
Subscribe to:
Posts (Atom)
