AnCaps
ANARCHO-CAPITALISTS
Bitch-Slapping Statists For Fun & Profit Based On The Non-Aggression Principle
 
HomePortalGalleryRegisterLog in

 

 Malware targets human rights activists

View previous topic View next topic Go down 
AuthorMessage
CovOps

CovOps

Female Location : Ether-Sphere
Job/hobbies : Irrationality Exterminator
Humor : Über Serious

Malware targets human rights activists Vide
PostSubject: Malware targets human rights activists   Malware targets human rights activists Icon_minitimeMon Dec 26, 2011 7:43 pm

Hackers have successfully compromised the UK version of Amnesty International's website by serving malware that exploits a recently-patched vulnerability in Java.



Malware targets human rights activists Matrixsentinel



According to security expert Brian Krebs, the site's home page is booby trapped with code that pulls a malicious script from an apparently hacked automobile site in Brazil. 



The car site serves a malicious Java applet that employs a public exploit to attack a well-known Java flaw. Essentially, the applet retrieves an executable file detected by Sophos antivirus as Trojan Spy-XR, a malware variant first identified in June 2011.



As Krebs notes, the latest incident is hardly the first time Amnesty's sites have been hacked to serve up malware. To be sure, the organization's site was compromised in April 2011 with a drive-by attack, while Amnesty's Hong Kong Web site was hacked and seeded with an exploit that dropped malware using a previously unknown IE vulnerability in November 2010.

"It appears likely that the exploit may be part of an ongoing campaign by Chinese hacking groups to extract information from dissident and human rights organizations," Krebs assessed.

Paul Royal, a research consultant with Barracuda Networks, expressed similar sentiments.

"Certain countries use zero day exploits and other techniques to gain electronic information about the activities of human rights activists," he explained.

"Of course, a subset of these activists are too smart to click on links in even well-worded spearphishing emails. But what if you compromised a website frequented by these activists (e.g., Amnesty International)? Then your targets come to you. The context-specific damage potential is significant."

http://www.tgdaily.com/security-features/60395-malware-targets-human-rights-activists
Back to top Go down
 

Malware targets human rights activists

View previous topic View next topic Back to top 
Page 1 of 1

Permissions in this forum:You cannot reply to topics in this forum
 :: Anarcho-Capitalist Categorical Imperatives :: AnCaps In Science, Technology & Environment-