R E L A T E D   C O N T E N T
ADVERTISEMENT

Ad-based Trojan hits MySpace, Bebo and others

Malware hidden in adverts

Matt Chapman, vnunet.com 11 Sep 2007
ADVERTISEMENT

Users of high profile sites including MySpace, The Sun, Bebo and PhotoBucket have been exposed to a Trojan hidden within adverts.

The sites all ran advertising in recent weeks from the Right Media online ad exchange which were unknowingly infected with the Downloader.VBS.Agent.n Trojan.

"This is another example of how legitimate 'trusted' websites can unknowingly host malware," said Dan Nadir, vice president of product strategy at ScanSafe.

"Online ads have become a primary target for malware authors because they offer a stealthy way to distribute malware to a wide audience."

Nadir explained that the malware was particularly dangerous because it required no user interaction for infection to take place.

ScanSafe estimates that up to 12 million ads may have been delivered, exposing a large number of users to the Trojan.

The security vendor saw a surge in blocks of the Trojan beginning on 8 August and continuing until early September.

Nadir added that it will be very difficult to track down the source of the malware because the hacker used the distributed nature of online advertising to spread the code to hundreds of sites.

One of the infected adverts used a Flash file to generate an invisible iFrame. This was linked to an IP address containing obfuscated visual basic script that used the well-known MDAC exploit to download a Trojan executable.

ScanSafe believes that the malicious script inside the Flash ad avoided detection by Right Media because of the clever use of a referrer check. This meant that the advert only became active when delivered by a particular ad server.

The Downloader.VBS.Agent.n malware downloads other programs which are launched on the victim's machine without knowledge or consent.

ScanSafe said that several well known sites, including TomsHardware, have unwittingly hosted malware that was inserted via infected online ads.

See also:

Quarter of all detected threats during August, says BitDefender  10 Sep 2007
Email links lead to malicious script and Trojan horse  30 Aug 2007
Not known how far infection has spread  23 Aug 2007
Experts warn of 'confirmation spam' outbreak  22 Aug 2007
Scammers bypassing authentication systems  06 Jul 2007

All Ecommerce

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
Senior C# Agile Web Developer, Online Gaming, London My Client provides adult customers with high quality gambling and gaming services in an environment that is convenient, entertaining, fair, regulated and secure. My Client is one ... more >
| Aston Carter
EMC, NetApps, West London, Media • NetApps FAS ... more >
| Abraxas
Data Analyst / MI Analyst – Leading Online Gaming Company A Data Analyst / Trafficker is sought by a leading online gaming company. The role encompasses all aspects of online advertising including data handling, communicating ... more >
| JAM Recruitment
Field Applications Engineer Power Electronics/Supplies Europe/Based Surrey Permanent Position £35-45k Basic+Bonus 10-15%+Car/Car allowance A global organisation involved with the design and development of power supplies actively requires a Field Applications Engineer to strengthen it existing ... more >
More job opportunities