Hackers unleash 'insidious' crimeware attack

Trusted websites turned into traps

Written by Robert Jaques

Security experts have warned of a crimeware attack that threatens to turn highly trusted websites into "insidious traps" for unwary visitors.

Finjan's Malicious Code Research Center said that more than 10,000 websites in the US were infected by this malware in December alone.

The attack, which the firm has designated 'random js toolkit', is an " extremely elusive" Trojan that sends data from infected machines direct to the malware author.

Stolen data can include documents, passwords, surfing habits or any other sensitive information of interest to the criminal.

The JavaScript toolkit is created dynamically and changes every time it is accessed. This makes it almost impossible for traditional signature-based anti-malware products to detect.

Yuval Ben-Itzhak, chief technology officer at Finjan, explained that signature-based detection for dynamic script is ineffective.

"'Signaturing' the exploiting code itself is not effective, since these exploits change continually to stay ahead of current zero-day threats and available patches," he said.

"Keeping an up-to-date list of 'highly-trusted/doubtful' domains serves only as a limited defence against this attack vector."

Ben-Itzhak added that the 'random js toolkit' is an example of the recent trend among cyber-criminals to undermine 'trusted' websites.

"Studies in mid-2007 showed nearly 30,000 infected web pages being created every day," he said.

"About 80 per cent of pages hosting malicious software or containing drive-by downloads with damaging content were located on hacked legitimate sites. Today the situation is much worse."

The 'random js attack' is performed by dynamically embedding scripts into a webpage, providing a random filename that can be accessed only once.

This dynamic embedding is done in such a selective manner that when a user has received a page with the embedded malicious script once, it will not be referenced again on further requests.

This method prevents detection of the malware in later forensic analyses.

Tags:

Further reading

Cyber-crooks target chat platforms

Unique threats soar in 2007   More...

MySpace page pushes fake Microsoft update

Dodgy profile hosting 'malware cocktail'   More...

New Year resolutions for security managers

Time to push security up the IT agenda   More...

'Sick' new scam targets non-profits

Beware fake philanthropists   More...

Related articles

'Wave of Trojans' goes on the rampage

Corporate IT managers urged to be on their guard   More...

Cyber-crooks turn to managed services

Easy-to-use crime-ware toolkits on the rise   More...

Hackers turn to new genre of evasive attacks

Finjan report warns of malicious code 'affiliation networks'   More...

Cyber-criminals unleash botnet swarms

Attacks designed to fly in under the corporate radar   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

13 May 2008

3.06 MBBloody students, goodbye to Dixons and hacking excuses More...

BusinessGreen.com podcast logo

13 May 2008

1.82 MBEco-Entrepreneur introduction More...

12 May 2008

2.4 MBMicrosoft's battles, data breach fines and website rip-offs More...

Poll

DATA ENCRYPTION

DATA ENCRYPTION

Should encryption be mandatory for all personal data held by companies and governments?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

BlackBerry Bold

RIM unveils slimmed-down BlackBerry Bold

New handset due this summer   More...

BlackBerry Bold

BlackBerry Bold takes on 3G iPhone

New models go head-to-head, says analyst   More...

Advertisement

HP

HP 'in talks' to buy EDS

Company offering upwards of $12bn   More...

Virgin Media

Virgin prepares 50Mbps launch in 2008

Successful trial clears network for higher speeds   More...

Advertisement