R E L A T E D   C O N T E N T
ADVERTISEMENT

Hackers unleash 'insidious' crimeware attack

Trusted websites turned into traps

Robert Jaques, vnunet.com 14 Jan 2008
ADVERTISEMENT

Security experts have warned of a crimeware attack that threatens to turn highly trusted websites into "insidious traps" for unwary visitors.

Finjan's Malicious Code Research Center said that more than 10,000 websites in the US were infected by this malware in December alone.

The attack, which the firm has designated 'random js toolkit', is an " extremely elusive" Trojan that sends data from infected machines direct to the malware author.

Stolen data can include documents, passwords, surfing habits or any other sensitive information of interest to the criminal.

The JavaScript toolkit is created dynamically and changes every time it is accessed. This makes it almost impossible for traditional signature-based anti-malware products to detect.

Yuval Ben-Itzhak, chief technology officer at Finjan, explained that signature-based detection for dynamic script is ineffective.

"'Signaturing' the exploiting code itself is not effective, since these exploits change continually to stay ahead of current zero-day threats and available patches," he said.

"Keeping an up-to-date list of 'highly-trusted/doubtful' domains serves only as a limited defence against this attack vector."

Ben-Itzhak added that the 'random js toolkit' is an example of the recent trend among cyber-criminals to undermine 'trusted' websites.

"Studies in mid-2007 showed nearly 30,000 infected web pages being created every day," he said.

"About 80 per cent of pages hosting malicious software or containing drive-by downloads with damaging content were located on hacked legitimate sites. Today the situation is much worse."

The 'random js attack' is performed by dynamically embedding scripts into a webpage, providing a random filename that can be accessed only once.

This dynamic embedding is done in such a selective manner that when a user has received a page with the embedded malicious script once, it will not be referenced again on further requests.

This method prevents detection of the malware in later forensic analyses.

See also:

Time to push security up the IT agenda  14 Jan 2008
Unique threats soar in 2007  14 Jan 2008
MySpaceDodgy profile hosting 'malware cocktail'  14 Jan 2008
FAA concerned that passengers could hack flight systems  11 Jan 2008
Thief gets away with £10,000  11 Jan 2008
Beware fake philanthropists  14 Jan 2008

All Hacking

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Sandiacre, Nottinghamshire, United Kingdom | NHS Midlands
Workstream Lead Requirement, Design, Build and Test (Business Analyst) Strategic IM&T - Delivery   Band 7:      £29,091 - £38,352 per annum Hours:       37.5 per week Base:         Octavia House, Sandiacre Job Ref:     973 - 080810   ... more >
London, United Kingdom | MRC Centre of Epidemiology for Child Health
Senior Information Systems Consultant - £34,793 - £41,545 pa - London Applications are invited for the exciting new post of Senior Information Systems Consultant at the MRC Centre of Epidemiology for Child Health, located within the Centre ... more >
Reading, Berkshire, United Kingdom | EDS
Position # 396477 Environment Support Engineer Location - Reading Job Description: There is an initial requirement an Environment Support Engineer to provide support and maintenance for the development environments within ATLAS. This role encompases many ... more >
London, United Kingdom | Utilyx
Senior Business Analyst - London Highly professional individual capable of working at senior / board level with blue chip clients - shaping and driving the analysis and design of their energy management solutions Proven capability ... more >
More job opportunities