Hackers Compromise 40,000 Web Sites

Researchers at Websense are reporting a mass compromise that may have affected as many as 40,000 Websites.

Although Websense would not name any of the compromised sites, researchers said the victims did not include any “big-name government or business sites.” The compromised sites are redirecting users to typo-squatted misspellings of legitimate Google Analytics domains. From there, users are redirected to the malicious Beladen.net site.

“The Google Analytics site serves as a statistics keeper, and the Beladen site is used to host the exploits,” said Stephan Chenette, manager of security research for Websense Security Labs. “It analyses the end-user PC and attempts to exploit several different unpatched vulnerabilities … If none of the unpatched vulnerabilities exist, it delivers a popup claiming that the PC is infected in an attempt to trick the user into installing rogue anti-virus software.”

According to Websense, the Beladen site is stacked with multiple types of malware—as many as 15 to 20 different exploits targeting various vulnerabilities.

Just how the legitimate Websites are being compromised is unclear, though Websense researchers speculate that it is a SQL injection issue.

“We haven’t pieced together the common software or common application that all these Websites are running that allows this SQL injection to happen,” Chenette said. “They’re either running some kind of business application that they have in common … or these [FTP] accounts were compromised and that’s how attackers are able to inject code into these Websites.”

“RBN (Russian Business Network) actually used this exact same domain,” he continued. “So the patterns that they are using in terms of the domain name and the exploits that they are using are very indicative that the group responsible behind this might be either connected with RBN, might be RBN themselves or might be a copycat group that is using some of the resources that RBN used.”

Brian Prince eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved

Recent Posts

EU Widens Investigations Into Chinese Imports, Subsidies

After the United States imposes 100 percent tariffs on certain Chinese goods, Europe widens its…

1 day ago

Reddit Deal With OpenAI Gives ChatGPT Access To Content

OpenAI strikes deal with Reddit to train its AI tech on user posts and give…

1 day ago

Microsoft Invests 4 Billion Euros In France For AI, Cloud

Global spending spree from Microsoft continues, with huge investment for new data centre to drive…

1 day ago

Toshiba Axes 4,000 Staff In Post-Delisting Restructuring Operation

Workforce blow. Newly privatised Toshiba has embarked on a 'revitalisation plan' that will entail the…

2 days ago

European Union Opens Child Safety Probe Into Meta

European Commission opens an official child safety investigation into Facebook and Instagram-owner Meta Platforms

2 days ago