Amnesty International's UK website served up Gh0st RAT for two days

Powered by SC Magazine
 

Injected via Java.

The Amnesty International UK website was recently compromised for two days to serve the Gh0st RAT.

Injected via the Java exploit that led to the creation of the Apple Flashback botnet, Websense said that during 8-9 May, website users risked having sensitive data stolen and perhaps infecting other users. The issue was rectified.

Websense said that once an exploit is successful, a file download is initiated from a URL that includes an executable that creates a new binary file in the Windows system directory.

“Analysing this low AV detected binary file, we recognise that this is a variant of the well-known remote administration tool Gh0st RAT, which is used mainly in targeted attacks to gain complete control of infected systems,” it said.

This allows the controller to access a user's files, email, passwords and other sensitive personal information.

Carl Leonard, senior manager of Websense Security Labs, said: “Exploit kits zoom in on vulnerable websites, even ones with good intentions. With a low anti-virus detection rate, Gh0st RAT is a powerful tool that allows backdoor access into infected machines.

“Companies need effective real-time security to protect against infection. Without the right defences, it might be much more than a charity donation that the malware authors steal.”

This article originally appeared at scmagazineuk.com

Copyright © SC Magazine, UK edition


Amnesty International's UK website served up Gh0st RAT for two days
 
 
 
Top Stories
Qld Transport to replace core registration system
State's biggest citizen info repository set for overhaul.
 
Innovating in the sleepy super industry
There’s little incentive to be on the bleeding edge, so why is Andrew Todd fighting so hard?
 
How technology will unify Toll
The systems headache formed through 15 years of acquisitions.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
Who do you trust most to protect your private data?







   |   View results
Your bank
  39%
 
Your insurance company
  3%
 
A technology company (Google, Facebook et al)
  7%
 
Your telco, ISP or utility
  8%
 
A retailer (Coles, Woolworths et al)
  2%
 
A Federal Government agency (ATO, Centrelink etc)
  20%
 
An Australian law enforcement agency (AFP, ASIO et al)
  15%
 
A State Government agency (Health dept, etc)
  5%
TOTAL VOTES: 884

Vote