Tuesday, June 19, 2007

'Italian Job' Trojan infecting thousands of servers, end-user PCs

A fast-moving, large-scale Trojan attack using the MPACK web exploit toolkit has infected nearly 10,000 web pages and downloaded malware on end-user PCs, according to security researchers at Trend Micro and Websense.

Source: SC Magazine / Jim Carr

Called the "Italian Job" by Trend Micro researchers because a great majority of the infected pages are hosted in Italy, the Trojan downloads a keylogger designed to steal banking and other confidential information through a wide range of web-infection downloads. David Perry, global director of education for Trend Micro, said the infection vector "was built from a kit sold commercially in Russia."

The original attack came "from Hong Kong, [but the hackers] set up a server in San Francisco that relays to one in Chicago," said Perry. "The infected websites are taken over to the point where they're owned by whomever the hackers are."

According to Trend Micro, tens of thousands of unaware users have already accessed compromised web pages, infecting their systems with the Trojan. The downloaded malware takes advantage of a vulnerability in so-called "iFrames" that are commonly used and exploited on websites.

Continue here ...



Digg! Post to del.icio.us Add to Technorati Favorites Webnews LinkARENA - Web 2.0 Social Bookmarking Service

0 comments:

Post a Comment