Wednesday, September 17, 2014
Search
  
Submit your own News for
inclusion in our Site.
Click here...
Breaking News
PMC Delivers 16-port SAS and SATA Storage Controllers
Google, Facebook and Twitter Collaborate On TODO Project
NBA 2K15 Allows You To Put Your Face Into The Game
Latest Cyberlink PowerDirector Offers Cloud Storage Features
Apple iOS 8 Coming On Wednesday
Latest Intel LTE Chipset Certified on China Mobile
ZTE Brings Its Supersized ZMax Smartphone To The US Market
Sony Slashes Guidance Due To Poor Smartphone Sales
Active Discussions
Yamaha CRW-F1UX
help questions structure DVDR
Made video, won't play back easily
Questions durability monitor LCD
Questions fungus CD/DVD Media, Some expert engineer in optical media can help me?
CD, DVD and Blu-ray burning for Android in development
IBM supercharges Power servers with graphics chips
Werner Vogels: four cloud computing trends for 2014
 Home > News > General Computing > Java Ex...
Last 7 Days News : SU MO TU WE TH FR SA All News

Tuesday, January 15, 2013
Java Exploit Behind "Red October" Cyber Attacks


Security researchers from Seculert discovered that the attackers of the large-scale cyberespionage operation dubbed "Red October" were taking advantage of Web-based Java exploits as well as malicious Excel and Word documents.

Kaspersky Lab's researchers published the results of their investigation into Red October on Monday. According to their report, the victims were targeted via rogue email messages that contained malicious documents designed to exploit known vulnerabilities in Microsoft Excel and Word.

However, after investigating the Command-and-Control (C2) servers used in the "Red October" campaign, Seculert researchers identified a special folder used by the attackers for an additional attack vector. In this vector, the attackers sent an email with an embedded link to a specially crafted PHP web page. This webpage exploited a vulnerability in Java (CVE-2011-3544), and in the background downloaded and executed the malware automatically, the researchers said.

The discovery was made possible because the attackers switched from using PHP as the server-side scripting language on their command and control servers to CGI. Some older PHP-based attack pages were still left on the servers and accessing them in a browser revealed their source code, the Seculert researchers added.

Further analysis is impossible at this time because the command and control servers have been shut down, most likely by the attackers in an attempt to cover their tracks, Seculert's researchers added.

The attack pages, the Java exploit itself and even the URL for the malware payload contained strings referencing "news," in an effort to trick the victims.


Previous
Next
Microsoft Advances the Cloud OS With New Management Solutions        All News        564 Million Chinese Have Internet Access
Microsoft Advances the Cloud OS With New Management Solutions     General Computing News      564 Million Chinese Have Internet Access

Get RSS feed Easy Print E-Mail this Message

Related News
Dropbox, WordPress Used To Spread Malware
Microsoft Says Viruses Are Back On The Rise
First Targeted Attack Utilising Malware for Android Devices Reported
Cyber Attack Targets Nato, Government Websites
Stuxnet Roots Found Back in 2005
FTC Warns Small Businesses Of Spam Email
Kaspersky Says 'Red October' Virus Has Been Targeting Diplomatic and Government Agencies
Kaspersky Discovers New version Of Flams Virus
Microsoft Warns Of New IE Security Breach
Microsoft Disrupts Nitol Botnet
Kaspersky Discovers New IT Virus Linked To Stuxnet
Microsoft Researcher Warns of Android 'botnet'

Most Popular News
 
Home | News | All News | Reviews | Articles | Guides | Download | Expert Area | Forum | Site Info
Site best viewed at 1024x768+ - CDRINFO.COM 1998-2014 - All rights reserved -
Privacy policy - Contact Us .