iTnews
  • Home
  • News
  • Technology
  • Security

'Italian job' attacks pick up steam

By Shaun Nichols
Jun 19 2007 11:50AM
Follow google news

GLOBAL - Ten thousand websites now unknowingly host mailicous attack.

'Italian job' attacks pick up steam
A rash of web-based attacks that www.vnunet.com is quickly expanding and has now infected 10,000 website around the world.

When security researchers first noticed the threat, it has affected 1,000 Englished language websites that were all in .it domain for Italy. By Monday however, the attack had gone worldwide and had drawn the attention of the FBI.

The attackers behind the vulnerability use known exploits in webserver applications to post attack code on third party websites. The actual attack is carried out when a user visits a compromised site. It then redirects the user to another server that runs MPack, a web-based attack tool that delivers an exploit specially designed to target flaws in each individual user's web browser. The exploit installs spyware and a keylogger.

Traffic is bounced from the compromised sites to a server in the San Francisco Bay Area which then redirects to the attack server which is currently located in Chicago, according to Paul Ferguson, a network architect with security vendor Trend Micro.

Ferguson noted that the San Francisco server uses an IP address registered to an Hong Kong entity, and is hosted by a company that is notoriously slow in responding to complaints about illegal activities on its network. Because law enforcement is currently investigating the case, the name of the hosting service could not be disclosed.

Even though the attacks are carried out in the US, Ferguson said that the commercial status of the MPack tool makes it difficult to pinpoint the location of the criminals responsible for the attacks. The attack code sells on message boards for anywhere from US$700 to US$1000.

Whoever is responsible for the attacks did not launch them on a whim, noted Ferguson. The prevalence of affected sites, the use of a host that is known for harboring criminals, and the fact that the attack was launched at the end of the work-week are all indications that the operation was planned out extensively, he argued.

Fully patched systems however should be safe, because none of the vulnerabilities targeted by the MPack tool are zero-day flaws.

Both Trend Micro and Symantec recommend that users install all current vendor patches for both their operating systems and browsers. Trend Micro also recommends that network administrators implement both HTTP and spyware scanning systems, as well as restrict the ability of network users to load and unload device drivers.

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.
Copyright ©v3.co.uk
Tags:
attacksitalianjobpicksecuritysteamup

Related Articles

  • Anthropic pulls Mythos-class models globally Anthropic pulls Mythos-class models globally
  • AudiA6 crypto launderers arrested, network taken down by police AudiA6 crypto launderers arrested, network taken down by police
  • US charges suspected Russian hacker with facilitating cyber campaign US charges suspected Russian hacker with facilitating cyber campaign
  • Gov looks for upstream threat blocking by telcos, cloud operators Gov looks for upstream threat blocking by telcos, cloud operators
Join our WhatsApp Channel

Partner Content

CommBank creates opportunities for technologists to upskill  with frontier AI companies
Partner Content CommBank creates opportunities for technologists to upskill with frontier AI companies
Agile isn’t the problem: why projects still fail, and what’s missing
Partner Content Agile isn’t the problem: why projects still fail, and what’s missing
The hidden economics of AI: Why token usage matters more than you think
Partner Content The hidden economics of AI: Why token usage matters more than you think
Intelligence × Trust: the equation that will decide Australia's AI winners
Promoted Content Intelligence × Trust: the equation that will decide Australia's AI winners

Sponsored Whitepapers

Are Australian organisations as cyber-ready as they think?
Are Australian organisations as cyber-ready as they think?
Are New Zealand organisations as cyber-ready as they think?
Are New Zealand organisations as cyber-ready as they think?
From visibility to execution:  Fixing the SaaS management gap
From visibility to execution: Fixing the SaaS management gap
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • Forrester's AI Forum Sydney Forrester's AI Forum Sydney
  • The 2026 iAwards The 2026 iAwards
  • Integrate 2026 Integrate 2026
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Anthropic releases Mythos-class model for public use

Anthropic releases Mythos-class model for public use

Apple bumps up security in fresh operating system releases

Apple bumps up security in fresh operating system releases

Anthropic opens Claude Mythos Preview AI program to Australia

Anthropic opens Claude Mythos Preview AI program to Australia

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.