Showing posts with label Angler ExploitKit. Show all posts
Showing posts with label Angler ExploitKit. Show all posts

Wednesday, 12 August 2015

IE Vulnerability Used To Distribute Ransomware


A vulnerability in Internet Explorer that Microsoft only three weeks ago patched is now actively used to infect computers with ransomware. The vulnerability exists in IE6 to IE11. Visiting a malicious or hacked website or see getting an infected ad is enough for an attacker to install malware on the computer for example.

The exploit that uses the vulnerability has been developed by the creators of the Angler Exploitkit. According to security researcher ' JuK 'of the blog Malware do not need Coffee makers could possibly since July 24 with the development of the exploit have been busy, two days after the release of the update. The makers of Angler developed previously often very quickly just exploits for unpatched vulnerabilities in Adobe Flash Player. Many Internet users are slow to patch. Even though there are security updates available, there are still computers are not up-to-date and can be attacked.

Adobe

According to security firm FireEye is noteworthy that the creators of the Angler Exploitkit now suddenly focus on an IE vulnerability. In recent months, were in fact only developed exploits for Flash Player vulnerabilities, with an exploit for Microsoft Silverlight as an exception. One possible explanation, according to the security at the security measures Adobe has taken to prevent abuse of vulnerabilities.

Depending on the software installed Internet, try the Angler Exploitkit attacks through vulnerabilities in Flash Player, Silverlight and Internet Explorer. In case the attack is successful CryptoWall-ransomware is installed. This ransomware encrypts files on the computer and then asks for a fee to decrypt them.

Sunday, 12 July 2015

New Flash Player Flaw Hacking Team Actively Attacked


The Italian Hacking Team appears to have over many more unknown vulnerabilities in Adobe Flash Player than the one that was unveiled earlier this week and one of these leaks is now actively attacked by cyber criminals and an update from Adobe is not yet available.

Thereby running millions of Internet users risk. The situation looks like a repeat of the scenario that played out earlier this week. An attacker managed to break into Hacking Team and made ​​as 400GB of data booty. The data has a zero-day vulnerability for Flash Player encountered. After the discovery added to all kinds of so-called criminals who exploit kits with Internet attack . Adobe then came up with a patch to fix it.

Two new zero days

In the archives of Hacking Team researchers have now two new "zero-day vulnerabilities" found and made ​​public. The vulnerabilities in Adobe Flash Player version 18.0.0.204 and earlier are designated by the CVE numbers CVE-2015-5122 and CVE-2015-5123. One of these vulnerabilities, CVE-2015-5122, cyber criminals have been added to the Angler Exploitkit, reports researcher JuK of the blog Malware Do not Need Coffee. The code has also been added to Metasploit, a program for security professionals and penetration testers can test the security of networks and systems.

Thereby running Internet with Flash Player when visiting a hacked or malicious Web site, see getting infected ads or open a Word document with an embedded Flash file the risk of becoming infected with malware. As this week will come with Adobe emergency patch. However, to be published next week, as the software company in the late notice know, although the advisory refers to the week of 12 July. In the meantime, Internet users can protect themselves by temporarily disabling Flash Player.

Update

The CERT Coordination Center (CERT / CC) at Carnegie Mellon University warns also of vulnerability and allows users to protect themselves from the free Microsoft EMET to install or not to implement Flash content from unreliable.