Original URL: http://www.channelregister.co.uk/2008/01/23/embassy_sites_serve_malware/
Add embassy websites to the growing list of hacked internet destinations trying to infect visitor PCs with malware.
Earlier this week, the site for the Netherlands Embassy in Russia (http://www.netherlands.ru/) was caught serving a script that tried to dupe people into installing software that made their machines part of a botnet, according to Ofer Elzam, director of product management for eSafe (http://www.aladdin.com/esafe/default.aspx), a business unit of Aladdin that blocks malicious web content from its customers' networks. In November the Ministry of Foreign Affairs of Georgia (http://mfa.gov.ge/) and Ukraine Embassy Web site (http://ukrembassy.5ci.lt/) in Lithuania were found to be launching similar attacks, he says.
All three sites had been hacked to include invisible iframes that initiated a chain of links that ultimately connected to servers hosting malicious code, which was heavily obfuscated to throw off antivirus systems. The similarities led eSafe researchers to conclude the attacks were carried out by the same group. Elzam speculates the group has ties to organized crime in Eastern Europe.
The findings come as Websense, a separate security firm that's based in San Diego, recently estimated that 51 per cent of websites hosting malicious code over the past six months were legitimate destinations that had been hacked, as opposed to sites specifically set up by criminals. Compromised websites can pose a greater risk because they often come with a degree of trust.
Stories reporting security vulnerabilities frequently carry the caveat that an attacker would first need to lure a victim to a malicious website. Poisoning the pages of a legitimate embassy or ecommerce website would be one way to carry that out.
Frequently, the compromised websites launch code that scours a visitor's machine for unpatched vulnerabilities in Windows or in applications such as Apple's QuickTime media player. Such was the case in two recent hacking sprees (here (http://www.theregister.co.uk/2008/01/11/mysterious_web_infection/) and here (http://www.theregister.co.uk/2008/01/08/malicious_website_redirectors/)) that affected hundreds of thousands of sites, including those of mom-and-pop ecommerce companies and the City of Cleveland.
But in the case of the Netherlands Embassy, the attackers simply included text that instructed visitors to download and install the malware. Of course, no self-respecting Reg reader would fall for such a ruse. But sadly, Elzam says, because the instruction is coming from a trusted site, plenty of less savvy users do fall for the ploy. Saps.
"Using social engineering is almost fool proof," he says. "My mother would fall for that because she is really conditioned to click on OK when she's asked to do something like that." ®
Harman hack horror has blog backing Boris (25 April 2008)
http://www.theregister.co.uk/2008/04/25/harriet_harman_website_hacked/
LSDigital drops federal botnet confession (14 March 2008)
http://www.theregister.co.uk/2008/03/14/bot_herder_cops_plea/
Rent-a-bot gang rises from the DDoS ashes (13 March 2008)
http://www.channelregister.co.uk/2008/03/13/loadscc_rises_again/
Hackers seed malware on Indian anti-virus site (8 February 2008)
http://www.channelregister.co.uk/2008/02/08/indian_av_site_compromise/
Forth Road Bridge hack redirects to smut bazaar (7 February 2008)
http://www.channelregister.co.uk/2008/02/07/forth_bridge_hack/
Perl.com sends visitors to porn link farm (19 January 2008)
http://www.channelregister.co.uk/2008/01/19/perl_site_redirects_to_porn_site/
Mystery web infection grows, but cause remains elusive (16 January 2008)
http://www.channelregister.co.uk/2008/01/16/mysterious_web_infection_continues/
Mass web infection leaves researcher scratching her head (11 January 2008)
http://www.channelregister.co.uk/2008/01/11/mysterious_web_infection/
Hackers turn Cleveland into malware server (8 January 2008)
http://www.theregister.co.uk/2008/01/08/malicious_website_redirectors/
Beware of pickpockets and malware-laced banner ads (4 January 2008)
http://www.channelregister.co.uk/2008/01/04/malware_laced_banners/
Indonesian hacker touches souls by bringing down police website (20 December 2007)
http://www.theregister.co.uk/2007/12/20/tuscon_police_website_defacement/
Tor embassy 'hacker' raided by Swedish Feds (15 November 2007)
http://www.channelregister.co.uk/2007/11/15/tor_hacker_arrest/
Tor at heart of embassy passwords leak (10 September 2007)
http://www.channelregister.co.uk/2007/09/10/misuse_of_tor_led_to_embassy_password_breach/
Mystery SNAFU exposes email logins for 100 foreign embassies (and counting) (31 August 2007)
http://www.theregister.co.uk/2007/08/31/embassy_email_accounts_exposed/
© Copyright 2008