Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« Ohio Data Breach Shows Backups Vulnerabilities | Main | Microsoft Gives Users Choice, When It Has To »

Italian Job Attack Uses "Commercial" Malware Delivery Platform

Earlier posts in this blog have discussed the professional, business like nature of cybercrime, here is a case in point.

Legitimate Web sites in Europe, especially Italy, are being compromised with a combination of simple HTML iFrame code and a malware delivery tool called MPack. MPack exploits known bugs and attacks Internet Explorer, Firefox and Opera. As of yesterday 10,000 Web sites had been comprimised.

What makes this story noteworthy is the way MPack looks less and less like a piece of hacked code left for script kiddies and more like a commercial application, complete with update support. Help Net Security describes MPack:

This tool is sold through online forums for around $700. With each version, the creators offer one year’s free support.

“Mpack offers the type of features you would expect from a legal application. For example, client updates. These updates, effectively different versions of the application, are actually the exploits needed to take advantage of the latest vulnerabilities discovered. There is normally a new one every month and they cost between $50 and $150,” explains Luis Corrons, Technical Director of PandaLabs.

For another $300, clients are also offered DreamDownloader. This is a tool designed to create downloader Trojans. It works in the following way: The hacker tells DreamDownloader the URL in which the file is hosted (a Trojan, a worm, malware updates, etc.), and the utility automatically generates an executable to download it.

The PandaLab Blogs posted some stats on the spread of MPack last month which are no doubt lower than today's actual distribution.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/334

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net