Showing posts with label John Mancuso. Show all posts
Showing posts with label John Mancuso. Show all posts

Sunday, 23 August 2015

Thousands Of Hacked WordPress Sites Spread Ransomware


In recent weeks attackers have hacked more than 2600 unique WordPress sites and provide malicious code that attempt to infect visitors with ransomware. The hacked WordPress sites are all running version 4.2 of the software or older, says security firm Zscaler.

The attack on the WordPress sites consists of several steps. First, the site is accepted in full. So the attackers add a Webshell, and steal the credentials of the administrator. Is then added an iframe to the website that visitors to the WordPress site unnoticed a page with the Neutrino-exploitkit late charge. The iframe code only to users of Internet Explorer is shown. A cookie will prevent victims of the iframe code are offered several times.

To infect users makes the Neutrino-exploitkit using a malicious Flash file. In case Flash Player not installed on the computer, the user is offered an old Flash installation file, and the malicious file is loaded. Do not know how the installer will install exactly Zscaler allows the analysis of the attack.

In case the attack is successful, the ransomware CryptoWall-installed on the computer. This ransomware encrypts files on the computer and asks users a certain amount for decrypting. According to analyst John Mancuso WordPress remains an attractive target for cyber criminals. WordPress is a very popular free content management system used by more than 60 million websites, including about 23% of the Top 10 million websites on the internet.

Monday, 26 January 2015

Flash Users Attacked By Infected Ads


The zero-day vulnerability in Adobe Flash Player that this week was discovered and which is expected next week an emergency patch will be deployed against Internet via infected ads. Visiting a website that shows the infected ads with Internet Explorer or Firefox on any Windows version is basically enough to get infected with malware.

It does not matter whether a 32- or 64-bit Windows version used, as reported security firm Zscaler. The malicious ads would be distributed through ad networks and Adcash Oneclickads. As previously noted already infected computers part of a botnet, that the machine for advertising and click fraud efforts. "This is the first zero-day exploit for Adobe Flash Player this year and it's no surprise that it is spread via infected ads," said John Mancuso of Zscaler. Pending to update users get the advice to temporarily disable Flash Player.