Certificate phishing sucks bank customers into Blackhole

Powered by SC Magazine
 

Bank business customers warned of invalid certificates.

Spammers are telling bank business customers that their SSL certificates had expired in efforts to exploit the blacklisting of certificate authority DigiNotar.

DigitNotar was blacklisted by major browsers after it was hacked and issued fraudulent certificates.

Barracuda Networks security researchers Dave Michmerhuizen and Luis Chapetti said the spam carried a dangerous message.

"The spammers try to create a sense of urgency with the hope that you will click one of the links to see what happens; which in this case is a particularly bad idea because the second link in the message directs the browser to a server hosting an exploit kit," they said.

“Once the browser visits that site a series of attacks begin which can result in the download of Trojan.Buzus."

That malware payload stole login credentials and created a backdoor that allowed remote control of compromised machines.

Barracuda said that it is seeing more overtly malicious spam directing users to malicious sites since the Blackhole exploit kit became widely available earlier this year.

Websense Security Labs security research manager Carl Leonard said it was a low volume campaign of less than 100 messages.

“It took the user to a .scr file that delivered the exploits. But this shows that scammers are tuned into the hot topics."

“This is not a targeted attack in an advanced persistent threat style, but it looks like a phishing email but this is much more sinister as it delivers an exploit kit and not a standard phish."

He also said the Blackhole exploit kit was one of the most popular kits in the wild.

Blackhole was based on PHP and a MySQL backend and targeted Windows operating systems and applications.

It also allowed a malicious payload file's name to be changed to make it undetectable by anti-virus, while exploits were encrypted with custom algorithms.

This article originally appeared at scmagazineuk.com

Copyright © SC Magazine, US edition


Certificate phishing sucks bank customers into Blackhole
 
 
 
Top Stories
Westpac committed to core banking plan
[Blog post] Now with leadership.
 
The True Cost of BYOD - 2014 survey
Twelve months on from our first study, is BYOD a better proposition?
 
Photos: Unboxing the Magnus supercomputer
Pawsey's biggest beast slots into place.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
What is delaying adoption of public cloud in your organisation?







   |   View results
Lock-in concerns
  29%
 
Application integration concerns
  3%
 
Security and compliance concerns
  27%
 
Unreliable network infrastructure
  9%
 
Data sovereignty concerns
  22%
 
Lack of stakeholder support
  3%
 
Protecting on-premise IT jobs
  4%
 
Difficulty transitioning CapEx budget into OpEx
  3%
TOTAL VOTES: 1135

Vote