R E L A T E D   C O N T E N T
ADVERTISEMENT

Sharp hike in cyber-attacks from China

Finjan reports new wave of malicious activity

Robert Jaques, vnunet.com 17 Dec 2007
ADVERTISEMENT

Security experts have warned of a sharp hike in malicious activity coming out of China.

Finjan has examined the new wave of Chinese attacks and the mechanisms used, and claims to have identified an "intricate network of connections" between China-based servers run by cyber-criminals.

The security firm has discovered that the entry points that initiate the attack on users "in the wild" exist all over the world and are eventually associated with servers registered as Chinese domains.

The attackers are spreading the assaults by placing entry points on a variety of websites in different regions and listed differently by URL categorisation engines.

The infection consists of either an Iframe or a Script tag placed on the website that causes users visiting the site to be attacked.

Examples for such entry point regions are shown in Finjan's December 2007 Malicious Page of the Month Report, and were found on trusted websites in the US, China and Western Europe, including government and education sites.

After the victim reaches an entry point, the attackers use dynamic code obfuscation methods to limit signature-based technologies from detecting the attack.

The victim is redirected to a series of sites containing Iframes that will eventually force the victim to visit a site that belongs to the Chinese network.

In the first part of the actual malicious attack, the cyber-criminals use new or known exploits that will infect the victim with a crimeware Trojan.

"After the initial Trojan is loaded it initiates the downloading of other Trojans from different locations. The compromised computer will then redirect to other sites in order to send statistical information about the infected PC," the firm stated.

"Finjan has discovered that different Trojans send encoded information to the same sites in China that we identified as being unique to the attack."

See also:

Stealth malware dodges popular security products  13 Dec 2007
Compromised site used to push malware  14 Dec 2007
Majority admit to losing business data  12 Dec 2007
Security firm predicts trouble ahead for Apple's handset  11 Dec 2007
Porn overcomes Turing Test  10 Dec 2007

All Hacking

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
C# Web Developer, Finance, London Financial Services Required: C#, ASP.NET, AJAX Fantastic opportunity not to be missed!! This is a great opportunity to work on a unique objectives that no other company is doing working ... more >
| JAM Recruitment
Senior Hardware Engineer Scotland/Edinburgh Communication Systems Permanent Position 40-45K+Benefits A leading organisation involved with the design and development of data acquisition systems and synthesis boards for a range of radar, signal intelligence and software radio ... more >
| JAM Recruitment
FPGA Engineer Defence/Safety Critical Buckinghamshire Permanent Position 45K+Benefits A leading UK defence organisation requires an experienced digital design engineer to strengthen its existing development team due to a number of long-term projects that have recently ... more >
| JAM Recruitment
DSP Engineer 3 Months Contract Hertfordshire £Excellent Rates£ This position requires you to have experience of measurement algorithms development for the generation and analysis of digital wireless communication standards including GSM, EDGE, UMTS, WLAN and ... more >
More job opportunities