Showing posts with label targeted. Show all posts
Showing posts with label targeted. Show all posts

Wednesday, April 24, 2013

Recently patched Java flaw already targeted in mass attacks, researchers say



PCWorld - A recently patched Java remote code execution vulnerability is already being exploited by cybercriminals in mass attacks to infect computers with scareware, security researchers warn.

The vulnerability, identified as CVE-2013-2423, was one of the 42 security issues fixed in Java 7 Update 21 that was released by Oracle on April 16.

According to Oracle’s advisory at the time, the vulnerability only affects client, not server, deployments of Java. The company gave the flaw’s impact a 4.3 out of 10 rating using the Common Vulnerability Scoring System (CVSS) and added that “this vulnerability can be exploited only through untrusted Java Web Start applications and untrusted Java applets.”

However, it seems that the low CVSS score didn’t stop cybercriminals from targeting the vulnerability. An exploit for CVE-2013-2423 was integrated into a high-end Web attack toolkit known as Cool Exploit Kit and is used to install a piece of malware called Reveton, an independent malware researcher known online as Kafeine said Tuesday in a blog post.

More

Monday, July 2, 2012

New OS X Tibet Malware Appears to Be a Politically Motivated and Targeted Attack

Unlike other malware, this strain appears to be a politically motivated and targeted attack.



CNET - Security company Kaspersky Labs has intercepted a new variant of the Tibet malware for OS X, which is being distributed to specific Uyghur activist groups as part of a seemingly politically motivated APT (advanced persistent threat) attack.

The malware is being distributed in e-mails to certain Uyghur Mac users, and is contained within a ZIP file called "matiriyal.zip." If this file is opened it will reveal an image file and a text file that is a disguised OS X application that if run will install the malware. Once installed, the malware will connect to a command-and-control server based in China, and allow a remote attacker to issue local commands and access files.

The Tibet malware was initially found in March and initially used the same Java exploit that allowed the infamous Flashback attack to infect about 1 percent of Mac systems. Since then the malware has been released in variants that have exploited other known vulnerabilities, such as the MS09-027 vulnerability in Microsoft Office that was found and patched in 2009.    More