There is an increasing amount of Trojan infections occurring where the bad guys are taking scripts from legit websites, adding malicious code and, bam, you go to an infected site, researchers said.

The Trojan involved is the Trojan.JS.Blacole.Gen and it has an interesting malware distribution campaign, said researches from F-Secure.

RELATED STORIES
Spotlight on Yahoo Malware Attack
More Malware Working in Cloud
Cyber Attacks Top Threat to Nation
Securing ‘Internet of Things’

Cyber criminals go in and compromise a number of websites, 40 percent of which are from Germany. They then take the scripts from these sites and add malicious code.

When users visit the infected sites, they end up redirected to a page that instructs them to update their Flash Player in order to gain access to the content.

Schneider Bold

If the victim clicks on one of the Download Now links, a file called flashplayer.exe downloads from a SkyDrive account. When the user executes this file, a window which reads “Installing latest Flash Player” ends up displayed.

In the meantime, another piece of malware downloads from the same SkyDrive account.

At that point it is off to the races for the bad guys.

Click here for more information on the attack.

ISSSource

Pin It on Pinterest

Share This