Best Website-BuildersBest Website-Builders
    What's Hot

    11 Best Coffee Grinders (2023): Conical-Burr, Flat-Burr, Manual, Blade

    March 12, 2023

    England in Bangladesh: Jos Buttler defends tourists’ selections after Tigers clinch series

    March 12, 2023

    Silicon Valley Bank: Offer made for UK arm of failed US lender

    March 12, 2023
    Facebook Twitter Instagram
    Facebook Twitter Instagram
    Best Website-BuildersBest Website-Builders
    • Home
    • CSS

      Best AI Tools for Web Designers (2023)

      March 12, 2023

      PSPad 5.0.7.770 | Neowin

      March 11, 2023

      Battle of Memphis

      March 11, 2023

      How to create a recipe book using HTML, CSS and JavaScript

      March 11, 2023

      Cubist Systematic Strategies LLC Increases Holding in Hennessy Capital Investment Corp.

      March 11, 2023
    • Joomla

      Pros, Cons, & Pricing Compared

      March 11, 2023

      Give your website a place to call home for a lifetime of web hosting for just $100

      March 11, 2023

      Give your website a place to call home for a lifetime of web hosting for just $100

      March 11, 2023

      12 Best Free Web Hosting Sites to Choose From

      March 10, 2023

      cPanel vs SPanel: Which is the Better Web Hosting Control Panel?

      March 10, 2023
    • PHP

      Most Effective Skin Serum, According to Reviewers and Dermatologists

      March 12, 2023

      Man sues ex-wife’s friend for helping ex-wife get abortion

      March 11, 2023

      Perfect indoor and outdoor slippers to wear around the house or on errands

      March 11, 2023

      Review: Maggie Milner’s ‘Couplets’

      March 11, 2023

      “Hasta Cuando” by Kari Uchis, everyone’s favorite

      March 11, 2023
    • UX

      New York City worker saw company hiring for her job but paid $90,000 more

      March 11, 2023

      Best March Madness Apps of 2023: NCAA, ESPN, CBS

      March 11, 2023

      Best March Madness Apps of 2023: NCAA, ESPN, CBS

      March 11, 2023

      I found my job listing with a much higher salary, so I reapplied

      March 10, 2023

      I found my job listing with a much higher salary, so I reapplied

      March 10, 2023
    • Web Builders
      1. Web Design
      2. View All

      What Comes First in Website Development — Design or Copy?

      February 2, 2023

      Modern Campus Honors Best Higher Education Websites of 2022

      February 2, 2023

      Premier SEO Consultant in Las Vegas, Nevada with Unparalleled Customer Service

      February 2, 2023

      Can Religious Freedom Be Saved? This group is racing the clock to teach America’s first freedom

      February 2, 2023

      How i Create New Google Account

      February 7, 2023

      CWT powers tools for meeting and event planners

      January 31, 2023

      Best Website Builder – Website Builders

      January 24, 2023

      Is There A Market For Rap-Themed Slot Games? – Rap Review

      January 19, 2023
    • WordPress

      A big Samsung Galaxy S23 camera update is rumored to be in the works

      March 12, 2023

      Not impressed with the Oculus Quest 2? Here’s how the VR headset of the future beats it.

      March 12, 2023

      Sleep Week 2023 – 7 days tips for better sleep

      March 12, 2023

      These mobile games are just trying to steal your crypto assets, warns FBI

      March 12, 2023

      Latest Google Pixel 7a leak reveals mid-range photos and specs

      March 12, 2023
    • Realtoz
      • Our Other Sites
    • More News
    Best Website-BuildersBest Website-Builders
    Home » Thousands of Hacked Websites Infect Visitors with Malware – Ars Technica
    Joomla

    Thousands of Hacked Websites Infect Visitors with Malware – Ars Technica

    websitebuildersnowBy websitebuildersnowApril 11, 2018No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Thousands of Hacked Websites Infect Visitors with Malware

    Thousands of hacked websites unknowingly participate in a sophisticated scheme that uses fake update notifications to install banking malware and remote access Trojans on visitors’ computers. researchers announced on Tuesday.

    Running for at least four months, this campaign is capable of compromising websites running various content management systems, including WordPress, Joomla, and SquareSpace. This is according to a blog post by Malwarebytes lead his Malware Intelligence Analyst Jérôme Segura. According to him, the hackers sent a legitimate-looking message to a limited number of visitors to the site telling them to install an update for Firefox, Chrome, or Flash, depending on the browser they were using. to display.

    malware bytes

    To evade detection, attackers fingerprint potential targets to ensure, among other things, that bogus update notifications are delivered only once to a single IP address. Another piece of evidence of the attacker’s resourcefulness is that while update templates are hosted on hacked websites, carefully selected targets who fall for the scam download malicious JavaScript files from DropBox. is. JavaScript performs additional checks for potential VM and sandbox marks before delivering the final payload. The resulting executable is signed by a digital certificate trusted by the operating system, making the bogus notification appear legitimate.

    “This campaign leverages social engineering and relies on delivery mechanisms that abuse legitimate file hosting services,” wrote Segura. “Because the decoy file consists of a script rather than a malicious executable, the attacker has the flexibility to develop interesting obfuscation and fingerprinting techniques.”

    flying under the radar

    Attackers use highly obfuscated JavaScript to fly under the radar. Malicious software installed in the campaign included Chthonic banking malware and a Trojan horse version of the NetSupport commercial remote access application.

    malware bytes

    Malwarebytes was unable to pinpoint the exact number of compromised sites. Using a simple crawler script, researchers identified hundreds of compromised WordPress and Joomla sites and estimated that there were thousands of such infections. This query on the source code search engine PublicWWW revealed just over 900 compromised SquareSpace sites on Tuesday. By the time this post was published, that number had dropped to 774. This post by independent security researcher BroadAnalysis shows that the campaign was launched no later than December 20th, he said. The site was hacked because the operator was unable to install or follow through with available security updates. Other basic security measures, Segura said.

    Other internet posts also show the campaign in action. This Twitter thread from last month documents two compromised SquareSpace sites. In a post on his SquareSpace support forums on February 28th, another breach was reported, and another site administrator nearly experienced the same thing he did two weeks later.

    Campaigns using compromised websites to prey on visitors have become increasingly common over the past decade. These are typically used in computer support scams to trick people into paying money to fix nonexistent computer problems. Recently, compromised websites have been used to secretly mine cryptocurrency ransomware or malware. This fake update scam stands out because of its ability to remain hidden for at least four months, as well as its use of banking malware and backdoor Trojans.

    “The cloaking used in this campaign caught our attention because it stands out from other infection chains that are much less sophisticated and easier to identify and block,” said Segura. told Ars. “Another interesting point is the fact that such bogus updates are usually distributed via malvertising, which is usually cheap. One was tech support scams via browser lockers, which tend to be more serious malware such as stealers and remote administration tools.”





    Source link

    Share this:

    • Tweet
    • Email
    • Pocket
    • Mastodon
    • WhatsApp
    • Telegram
    • Share on Tumblr
    • Print
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleJoomla patches critical 8-year-old CMS bug
    Next Article Thousands of WP, Joomla, SquareSpace sites offering malicious updates
    websitebuildersnow
    • Website

    Related Posts

    Pros, Cons, & Pricing Compared

    March 11, 2023

    Give your website a place to call home for a lifetime of web hosting for just $100

    March 11, 2023

    Give your website a place to call home for a lifetime of web hosting for just $100

    March 11, 2023
    Add A Comment

    Leave a Reply Cancel reply

    Top Posts

    Subscribe to Updates

    Get the latest sports news from SportsSite about soccer, football and tennis.

    Advertisement
    Demo

    This website provides information about CSS and other things. Keep Supporting Us With the Latest News and we Will Provide the Best Of Our To Makes You Updated All Around The World News. Keep Sporting US.

    Facebook Twitter Instagram Pinterest YouTube
    Top Insights

    11 Best Coffee Grinders (2023): Conical-Burr, Flat-Burr, Manual, Blade

    March 12, 2023

    England in Bangladesh: Jos Buttler defends tourists’ selections after Tigers clinch series

    March 12, 2023

    Silicon Valley Bank: Offer made for UK arm of failed US lender

    March 12, 2023
    Get Informed

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    © 2023 bestwebsite-builders. Designed by bestwebsite-builders.
    • Home
    • About us
    • Contact us
    • DMCA
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.